2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43557MEDIUM5.3The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, th...
CVE-2022-43556MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field ...
CVE-2022-35260MEDIUM6.5curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white sp...
CVE-2022-35256MEDIUM6.5The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated wit...
CVE-2022-23143MEDIUM6.5ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an a...
CVE-2022-42706MEDIUM4.9An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified throu...
CVE-2022-42705MEDIUM6.5A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remo...
CVE-2022-43097MEDIUM5.4Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scriptin...
CVE-2022-23467MEDIUM4.6OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu...
CVE-2022-4293MEDIUM5.5Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.
CVE-2022-3926MEDIUM6.5The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secr...
CVE-2022-3909MEDIUM4.8The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3892MEDIUM4.8The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which ...
CVE-2022-3838MEDIUM4.8The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could a...
CVE-2022-3837MEDIUM4.8The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3830MEDIUM4.8The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-3677MEDIUM6.5The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which...
CVE-2022-3426MEDIUM4.8The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could al...
CVE-2022-4269MEDIUM5.5A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirect...
CVE-2022-45478MEDIUM5.9Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (...
CVE-2022-32634MEDIUM6.7In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o...
CVE-2022-32633MEDIUM6.7In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privi...
CVE-2022-32632MEDIUM6.7In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation ...
CVE-2022-32631MEDIUM6.7In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation ...
CVE-2022-32630MEDIUM6.7In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now