2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3105 | MEDIUM | 5.5 | 0.2% | Dec 14, 2022 | An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lac... |
| CVE-2022-3104 | MEDIUM | 5.5 | 0.2% | Dec 14, 2022 | An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks chec... |
| CVE-2022-31701 | MEDIUM | 5.3 | 0.5% | Dec 14, 2022 | VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the... |
| CVE-2022-23527 | MEDIUM | 6.1 | 0.9% | Dec 14, 2022 | mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Version... |
| CVE-2022-23520 | MEDIUM | 6.1 | 1.1% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there i... |
| CVE-2022-46073 | MEDIUM | 6.1 | 1.2% | Dec 14, 2022 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-23519 | MEDIUM | 6.1 | 1.0% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possi... |
| CVE-2022-23518 | MEDIUM | 6.1 | 0.9% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are ... |
| CVE-2022-4495 | MEDIUM | 6.1 | 0.5% | Dec 14, 2022 | A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue... |
| CVE-2022-23515 | MEDIUM | 6.1 | 0.8% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2022-3590 | MEDIUM | 5.9 | 3.1% | Dec 14, 2022 | WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition betwe... |
| CVE-2022-3073 | MEDIUM | 6.1 | 0.5% | Dec 14, 2022 | Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to... |
| CVE-2022-23504 | MEDIUM | 4.9 | 0.5% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 ... |
| CVE-2022-23502 | MEDIUM | 5.4 | 0.4% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When... |
| CVE-2022-23501 | MEDIUM | 6.5 | 0.5% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, ... |
| CVE-2022-42141 | MEDIUM | 5.4 | 0.5% | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter. |
| CVE-2022-44874 | MEDIUM | 5.5 | 0.3% | Dec 13, 2022 | wasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component o... |
| CVE-2022-46381 | MEDIUM | 6.1 | 1.7% | Dec 13, 2022 | Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_templat... |
| CVE-2022-43996 | MEDIUM | 5.4 | 0.5% | Dec 13, 2022 | The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload... |
| CVE-2022-38355 | MEDIUM | 5.5 | 0.4% | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to t... |
| CVE-2022-4207 | MEDIUM | 5.4 | 0.5% | Dec 13, 2022 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values th... |
| CVE-2022-38628 | MEDIUM | 6.1 | 0.9% | Dec 13, 2022 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered ... |
| CVE-2022-23499 | MEDIUM | 6.1 | 0.4% | Dec 13, 2022 | HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and val... |
| CVE-2022-44707 | MEDIUM | 6.5 | 2.5% | Dec 13, 2022 | Windows Kernel Denial of Service Vulnerability |
| CVE-2022-44699 | MEDIUM | 5.5 | 0.4% | Dec 13, 2022 | Azure Network Watcher Agent Security Feature Bypass Vulnerability |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now