2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42916 | HIGH | 7.5 | 1.6% | Oct 29, 2022 | In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl... |
| CVE-2022-43285 | HIGH | 7.5 | 0.7% | Oct 28, 2022 | Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disput... |
| CVE-2022-43284 | HIGH | 7.5 | 0.8% | Oct 28, 2022 | Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. ... |
| CVE-2022-43282 | HIGH | 7.1 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetRetur... |
| CVE-2022-43281 | HIGH | 7.8 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<w... |
| CVE-2022-43280 | HIGH | 7.1 | 0.3% | Oct 28, 2022 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDro... |
| CVE-2022-3708 | HIGH | 8.1 | 0.7% | Oct 28, 2022 | The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24.... |
| CVE-2022-3401 | HIGH | 8.8 | 1.6% | Oct 28, 2022 | The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include ... |
| CVE-2022-43233 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_... |
| CVE-2022-43232 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_... |
| CVE-2022-43231 | HIGH | 7.2 | 1.1% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_w... |
| CVE-2022-43230 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2022-43229 | HIGH | 7.2 | 1.1% | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2022-43228 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-41636 | HIGH | 7.5 | 0.4% | Oct 28, 2022 | Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted ... |
| CVE-2022-2475 | HIGH | 8.8 | 0.6% | Oct 28, 2022 | Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Comman... |
| CVE-2022-2474 | HIGH | 8 | 0.7% | Oct 28, 2022 | Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” ... |
| CVE-2022-2864 | HIGH | 8.8 | 0.5% | Oct 28, 2022 | The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2022-3697 | HIGH | 7.5 | 0.7% | Oct 28, 2022 | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2... |
| CVE-2022-37426 | HIGH | 7.5 | 0.5% | Oct 28, 2022 | Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content... |
| CVE-2022-43276 | HIGH | 7.2 | 0.7% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p... |
| CVE-2022-43275 | HIGH | 7.2 | 0.9% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_acti... |
| CVE-2022-3512 | HIGH | 8.8 | 0.4% | Oct 28, 2022 | Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" f... |
| CVE-2022-3337 | HIGH | 8.5 | 0.4% | Oct 28, 2022 | It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch... |
| CVE-2022-3322 | HIGH | 7.5 | 0.2% | Oct 28, 2022 | Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now