2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40011 | MEDIUM | 6.1 | 0.6% | Dec 23, 2022 | Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is ... |
| CVE-2022-47946 | MEDIUM | 5.5 | 0.4% | Dec 23, 2022 | An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring... |
| CVE-2022-4692 | MEDIUM | 5.4 | 0.6% | Dec 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-43849 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd k... |
| CVE-2022-43848 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfst... |
| CVE-2022-39164 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel ... |
| CVE-2022-43381 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX SMB cl... |
| CVE-2022-43380 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS k... |
| CVE-2022-40233 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP... |
| CVE-2022-39165 | MEDIUM | 6.2 | 0.2% | Dec 23, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a ... |
| CVE-2022-4698 | MEDIUM | 4.8 | 0.6% | Dec 23, 2022 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions u... |
| CVE-2022-4697 | MEDIUM | 4.8 | 0.7% | Dec 23, 2022 | The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_... |
| CVE-2022-47938 | MEDIUM | 6.5 | 58.5% | Dec 23, 2022 | An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-... |
| CVE-2022-44565 | MEDIUM | 5.3 | 0.4% | Dec 23, 2022 | An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0.... |
| CVE-2022-47524 | MEDIUM | 5.4 | 0.4% | Dec 23, 2022 | F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack. |
| CVE-2022-4690 | MEDIUM | 5.4 | 0.6% | Dec 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-4683 | MEDIUM | 6.5 | 0.4% | Dec 23, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-46492 | MEDIUM | 6.5 | 0.5% | Dec 23, 2022 | nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via... |
| CVE-2022-40897 | MEDIUM | 5.9 | 2.6% | Dec 23, 2022 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML... |
| CVE-2022-23513 | MEDIUM | 5.3 | 40.2% | Dec 23, 2022 | Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. I... |
| CVE-2022-47928 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp. |
| CVE-2022-46491 | MEDIUM | 6.5 | 0.3% | Dec 22, 2022 | A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allo... |
| CVE-2022-4662 | MEDIUM | 5.5 | 0.3% | Dec 22, 2022 | A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A ... |
| CVE-2022-43603 | MEDIUM | 5.9 | 1.3% | Dec 22, 2022 | A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2... |
| CVE-2022-43596 | MEDIUM | 5.9 | 1.1% | Dec 22, 2022 | An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Projec... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now