2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-43319HIGH7.5An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learnin...
CVE-2022-43318HIGH8.8Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit paramete...
CVE-2022-43306HIGH8.8The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party...
CVE-2022-37866HIGH7.5When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "...
CVE-2022-42956HIGH7.5The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
CVE-2022-42955HIGH7.5The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
CVE-2022-3558HIGH8The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it...
CVE-2022-3537HIGH8.8The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks,...
CVE-2022-3536HIGH8.8The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks,...
CVE-2022-3494HIGH8.8The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to ...
CVE-2022-3418HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allo...
CVE-2022-2711HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in upload...
CVE-2022-44794HIGH8.8An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote...
CVE-2022-42919HIGH7.8Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configur...
CVE-2022-37710HIGH7.8Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > Li...
CVE-2022-40284HIGH7.8A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution...
CVE-2022-42707HIGH7.5In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images ar...
CVE-2022-43567HIGH8.8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system c...
CVE-2022-43566HIGH8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more ...
CVE-2022-43565HIGH8.8In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notatio...
CVE-2022-43563HIGH8.8In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an at...
CVE-2022-38660HIGH8.8HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attack...
CVE-2022-43945HIGH7.5The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks ...
CVE-2022-40263HIGH7.8BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be ...
CVE-2022-39387HIGH7.5XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now