2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39019 | HIGH | 7.5 | 0.4% | Oct 31, 2022 | Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to u... |
| CVE-2022-39018 | HIGH | 7.5 | 0.4% | Oct 31, 2022 | Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r... |
| CVE-2022-39016 | HIGH | 8.8 | 0.5% | Oct 31, 2022 | Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an accoun... |
| CVE-2022-42925 | HIGH | 8.8 | 0.9% | Oct 31, 2022 | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol... |
| CVE-2022-42923 | HIGH | 8.8 | 0.6% | Oct 31, 2022 | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln... |
| CVE-2022-41776 | HIGH | 7.5 | 0.5% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the Writ... |
| CVE-2022-41688 | HIGH | 7.5 | 0.6% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that c... |
| CVE-2022-41681 | HIGH | 8.8 | 0.9% | Oct 31, 2022 | There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol... |
| CVE-2022-41644 | HIGH | 8.8 | 0.7% | Oct 31, 2022 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that chan... |
| CVE-2022-31690 | HIGH | 8.1 | 1.0% | Oct 31, 2022 | Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptibl... |
| CVE-2022-39294 | HIGH | 7.5 | 0.7% | Oct 31, 2022 | conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not ch... |
| CVE-2022-2741 | HIGH | 7.5 | 0.6% | Oct 31, 2022 | The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vuln... |
| CVE-2022-3380 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lea... |
| CVE-2022-3374 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP obje... |
| CVE-2022-3366 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2... |
| CVE-2022-3360 | HIGH | 8.1 | 1.8% | Oct 31, 2022 | The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticat... |
| CVE-2022-3357 | HIGH | 8.8 | 1.9% | Oct 31, 2022 | The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PH... |
| CVE-2022-3334 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP obj... |
| CVE-2022-3770 | HIGH | 8.8 | 0.5% | Oct 31, 2022 | A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in... |
| CVE-2022-37620 | HIGH | 7.5 | 1.1% | Oct 31, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnor... |
| CVE-2022-40617 | HIGH | 7.5 | 1.6% | Oct 31, 2022 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a craft... |
| CVE-2022-44019 | HIGH | 8.8 | 2.0% | Oct 30, 2022 | In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host... |
| CVE-2022-42915 | HIGH | 8.1 | 2.9% | Oct 29, 2022 | curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it set... |
| CVE-2022-41974 | HIGH | 7.8 | 0.6% | Oct 29, 2022 | multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conj... |
| CVE-2022-41973 | HIGH | 7.8 | 0.7% | Oct 29, 2022 | multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction w... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now