2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46160 | MEDIUM | 4.3 | 0.5% | Dec 13, 2022 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14... |
| CVE-2022-41915 | MEDIUM | 6.5 | 0.9% | Dec 13, 2022 | Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior ... |
| CVE-2022-23473 | MEDIUM | 4.3 | 0.5% | Dec 13, 2022 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14... |
| CVE-2022-41275 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link tha... |
| CVE-2022-41274 | MEDIUM | 6.5 | 0.6% | Dec 13, 2022 | SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application ... |
| CVE-2022-41273 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can... |
| CVE-2022-41266 | MEDIUM | 6.1 | 0.4% | Dec 13, 2022 | Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2... |
| CVE-2022-41263 | MEDIUM | 4.3 | 0.2% | Dec 12, 2022 | Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions... |
| CVE-2022-41262 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenti... |
| CVE-2022-41261 | MEDIUM | 5.5 | 0.2% | Dec 12, 2022 | SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a f... |
| CVE-2022-46906 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-46905 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary... |
| CVE-2022-46904 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-46903 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-4312 | MEDIUM | 5.5 | 0.1% | Dec 12, 2022 | A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could all... |
| CVE-2022-4311 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This coul... |
| CVE-2022-4097 | MEDIUM | 5.3 | 0.6% | Dec 12, 2022 | The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to by... |
| CVE-2022-4016 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, B... |
| CVE-2022-4010 | MEDIUM | 4.8 | 0.5% | Dec 12, 2022 | The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-4005 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow user... |
| CVE-2022-4004 | MEDIUM | 4.3 | 0.5% | Dec 12, 2022 | The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donat... |
| CVE-2022-4000 | MEDIUM | 4.8 | 0.5% | Dec 12, 2022 | The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could ... |
| CVE-2022-3946 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing an... |
| CVE-2022-3935 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any... |
| CVE-2022-3934 | MEDIUM | 5.4 | 0.9% | Dec 12, 2022 | The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pa... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now