2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31637 | HIGH | 7.8 | 0.1% | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ... |
| CVE-2022-31636 | HIGH | 7.8 | 0.1% | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ... |
| CVE-2022-31635 | HIGH | 7.8 | 0.1% | Jun 13, 2023 | Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ... |
| CVE-2022-42880 | MEDIUM | 6.1 | 0.2% | Jun 13, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cro... |
| CVE-2022-43953 | HIGH | 7.8 | 0.2% | Jun 13, 2023 | A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, ... |
| CVE-2022-43949 | HIGH | 7.5 | 0.4% | Jun 13, 2023 | A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthe... |
| CVE-2022-42478 | HIGH | 8.8 | 0.5% | Jun 13, 2023 | An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileg... |
| CVE-2022-42474 | LOW | 2.7 | 0.6% | Jun 13, 2023 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through ... |
| CVE-2022-41327 | MEDIUM | 4.4 | 0.1% | Jun 13, 2023 | A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.... |
| CVE-2022-39946 | HIGH | 7.2 | 0.7% | Jun 13, 2023 | An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions... |
| CVE-2022-33877 | MEDIUM | 5.5 | 0.2% | Jun 13, 2023 | An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 ... |
| CVE-2022-43778 | HIGH | 7.8 | 0.2% | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr... |
| CVE-2022-43777 | HIGH | 7.8 | 0.1% | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr... |
| CVE-2022-27541 | HIGH | 7.8 | 0.1% | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr... |
| CVE-2022-27539 | HIGH | 7.8 | 0.1% | Jun 12, 2023 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr... |
| CVE-2022-36331 | HIGH | 7.5 | 0.6% | Jun 12, 2023 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation ... |
| CVE-2022-38156 | HIGH | 7.2 | 1.3% | Jun 12, 2023 | A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband ... |
| CVE-2022-47140 | MEDIUM | 6.1 | 0.4% | Jun 12, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.1 versions. |
| CVE-2022-45827 | MEDIUM | 4.8 | 0.4% | Jun 12, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions. |
| CVE-2022-31693 | MEDIUM | 5.5 | 0.2% | Jun 7, 2023 | VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the V... |
| CVE-2022-4950 | HIGH | 8.8 | 1.4% | Jun 7, 2023 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that ... |
| CVE-2022-4949 | HIGH | 8.8 | 2.2% | Jun 7, 2023 | The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj... |
| CVE-2022-4948 | MEDIUM | 4.3 | 0.5% | Jun 7, 2023 | The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX... |
| CVE-2022-25834 | HIGH | 7.8 | 0.5% | Jun 7, 2023 | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could ... |
| CVE-2022-46165 | MEDIUM | 5.4 | 0.8% | Jun 6, 2023 | Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now