2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31637HIGH7.8Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ...
CVE-2022-31636HIGH7.8Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ...
CVE-2022-31635HIGH7.8Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC produ...
CVE-2022-42880MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cro...
CVE-2022-43953HIGH7.8A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, ...
CVE-2022-43949HIGH7.5A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthe...
CVE-2022-42478HIGH8.8An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileg...
CVE-2022-42474LOW2.7A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through ...
CVE-2022-41327MEDIUM4.4A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2....
CVE-2022-39946HIGH7.2An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions...
CVE-2022-33877MEDIUM5.5An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 ...
CVE-2022-43778HIGH7.8Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr...
CVE-2022-43777HIGH7.8Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr...
CVE-2022-27541HIGH7.8Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr...
CVE-2022-27539HIGH7.8Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC pr...
CVE-2022-36331HIGH7.5Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation ...
CVE-2022-38156HIGH7.2A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband ...
CVE-2022-47140MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.1 versions.
CVE-2022-45827MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions.
CVE-2022-31693MEDIUM5.5VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the V...
CVE-2022-4950HIGH8.8Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that ...
CVE-2022-4949HIGH8.8The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj...
CVE-2022-4948MEDIUM4.3The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX...
CVE-2022-25834HIGH7.8In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could ...
CVE-2022-46165MEDIUM5.4Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now