2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45077 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress. |
| CVE-2022-45069 | HIGH | 8.8 | 0.7% | Nov 17, 2022 | Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress. |
| CVE-2022-45066 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress. |
| CVE-2022-43506 | HIGH | 8.8 | 0.7% | Nov 17, 2022 | SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an atta... |
| CVE-2022-43457 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows a... |
| CVE-2022-43452 | HIGH | 8.8 | 7.7% | Nov 17, 2022 | SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows ... |
| CVE-2022-43447 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an... |
| CVE-2022-42533 | HIGH | 7.8 | 0.1% | Nov 17, 2022 | In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This ... |
| CVE-2022-41791 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. |
| CVE-2022-41775 | HIGH | 8.8 | 0.6% | Nov 17, 2022 | SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attack... |
| CVE-2022-40200 | HIGH | 8.8 | 0.9% | Nov 17, 2022 | Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. |
| CVE-2022-40192 | HIGH | 8.8 | 0.4% | Nov 17, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. |
| CVE-2022-39179 | HIGH | 7.2 | 1.0% | Nov 17, 2022 | College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed... |
| CVE-2022-36924 | HIGH | 7.8 | 0.2% | Nov 17, 2022 | The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr... |
| CVE-2022-36785 | HIGH | 7.5 | 1.9% | Nov 17, 2022 | D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file con... |
| CVE-2022-28768 | HIGH | 7.8 | 0.2% | Nov 17, 2022 | The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local priv... |
| CVE-2022-28766 | HIGH | 7.3 | 0.5% | Nov 17, 2022 | Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version ... |
| CVE-2022-23748 | HIGH | 7.8 | 9.1% | Nov 17, 2022 | mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from whi... |
| CVE-2022-45071 | HIGH | 8.8 | 0.3% | Nov 17, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress. |
| CVE-2022-44725 | HIGH | 7.8 | 0.2% | Nov 17, 2022 | OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. Th... |
| CVE-2022-43183 | HIGH | 8.8 | 1.6% | Nov 17, 2022 | XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController... |
| CVE-2022-43179 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa... |
| CVE-2022-43163 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43162 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-44403 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now