2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43319 | HIGH | 7.5 | 0.7% | Nov 7, 2022 | An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learnin... |
| CVE-2022-43318 | HIGH | 8.8 | 0.8% | Nov 7, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit paramete... |
| CVE-2022-43306 | HIGH | 8.8 | 1.0% | Nov 7, 2022 | The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party... |
| CVE-2022-37866 | HIGH | 7.5 | 1.6% | Nov 7, 2022 | When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "... |
| CVE-2022-42956 | HIGH | 7.5 | 0.4% | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password. |
| CVE-2022-42955 | HIGH | 7.5 | 0.4% | Nov 7, 2022 | The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials. |
| CVE-2022-3558 | HIGH | 8 | 1.0% | Nov 7, 2022 | The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it... |
| CVE-2022-3537 | HIGH | 8.8 | 0.5% | Nov 7, 2022 | The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks,... |
| CVE-2022-3536 | HIGH | 8.8 | 0.5% | Nov 7, 2022 | The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks,... |
| CVE-2022-3494 | HIGH | 8.8 | 1.2% | Nov 7, 2022 | The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to ... |
| CVE-2022-3418 | HIGH | 7.2 | 1.1% | Nov 7, 2022 | The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allo... |
| CVE-2022-2711 | HIGH | 7.2 | 3.2% | Nov 7, 2022 | The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in upload... |
| CVE-2022-44794 | HIGH | 8.8 | 1.0% | Nov 7, 2022 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote... |
| CVE-2022-42919 | HIGH | 7.8 | 0.6% | Nov 7, 2022 | Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configur... |
| CVE-2022-37710 | HIGH | 7.8 | 0.1% | Nov 7, 2022 | Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > Li... |
| CVE-2022-40284 | HIGH | 7.8 | 0.3% | Nov 6, 2022 | A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution... |
| CVE-2022-42707 | HIGH | 7.5 | 0.6% | Nov 6, 2022 | In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images ar... |
| CVE-2022-43567 | HIGH | 8.8 | 1.2% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system c... |
| CVE-2022-43566 | HIGH | 8 | 0.8% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more ... |
| CVE-2022-43565 | HIGH | 8.8 | 0.6% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notatio... |
| CVE-2022-43563 | HIGH | 8.8 | 0.6% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an at... |
| CVE-2022-38660 | HIGH | 8.8 | 0.3% | Nov 4, 2022 | HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attack... |
| CVE-2022-43945 | HIGH | 7.5 | 21.3% | Nov 4, 2022 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks ... |
| CVE-2022-40263 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be ... |
| CVE-2022-39387 | HIGH | 7.5 | 0.9% | Nov 4, 2022 | XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now