2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44449 | MEDIUM | 4.8 | 0.7% | Dec 21, 2022 | Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacke... |
| CVE-2022-43543 | MEDIUM | 5.4 | 0.5% | Dec 21, 2022 | KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handlin... |
| CVE-2022-25929 | MEDIUM | 5.4 | 0.8% | Dec 21, 2022 | The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user inp... |
| CVE-2022-4617 | MEDIUM | 6.1 | 0.6% | Dec 21, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2022-46318 | MEDIUM | 5.3 | 0.3% | Dec 20, 2022 | The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account remo... |
| CVE-2022-46313 | MEDIUM | 5.3 | 0.4% | Dec 20, 2022 | The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause u... |
| CVE-2022-43382 | MEDIUM | 4.4 | 0.2% | Dec 20, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the l... |
| CVE-2022-41590 | MEDIUM | 5.5 | 0.1% | Dec 20, 2022 | Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypas... |
| CVE-2022-39166 | MEDIUM | 4.9 | 0.6% | Dec 20, 2022 | IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IB... |
| CVE-2022-46771 | MEDIUM | 4.6 | 0.4% | Dec 20, 2022 | IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through... |
| CVE-2022-46430 | MEDIUM | 4.8 | 0.3% | Dec 20, 2022 | TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Deni... |
| CVE-2022-46428 | MEDIUM | 4.8 | 0.3% | Dec 20, 2022 | TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of... |
| CVE-2022-46422 | MEDIUM | 4.8 | 0.3% | Dec 20, 2022 | An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via... |
| CVE-2022-46139 | MEDIUM | 6.5 | 0.3% | Dec 20, 2022 | TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading ... |
| CVE-2022-39304 | MEDIUM | 4.7 | 0.4% | Dec 20, 2022 | ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for G... |
| CVE-2022-43875 | MEDIUM | 5.5 | 0.2% | Dec 20, 2022 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock ... |
| CVE-2022-43872 | MEDIUM | 5.3 | 0.5% | Dec 20, 2022 | IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows g... |
| CVE-2022-4619 | MEDIUM | 4.8 | 0.5% | Dec 20, 2022 | The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS c... |
| CVE-2022-47551 | MEDIUM | 6.5 | 0.6% | Dec 20, 2022 | Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The ro... |
| CVE-2022-46402 | MEDIUM | 6.5 | 0.5% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_r... |
| CVE-2022-46401 | MEDIUM | 5.4 | 0.7% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncR... |
| CVE-2022-46400 | MEDIUM | 5.4 | 0.6% | Dec 19, 2022 | The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers ... |
| CVE-2022-23543 | MEDIUM | 5.4 | 0.3% | Dec 19, 2022 | Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the si... |
| CVE-2022-23536 | MEDIUM | 6.5 | 0.8% | Dec 19, 2022 | Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex ve... |
| CVE-2022-43887 | MEDIUM | 5.3 | 0.5% | Dec 19, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API ke... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now