2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43557 | MEDIUM | 5.3 | 0.2% | Dec 5, 2022 | The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, th... |
| CVE-2022-43556 | MEDIUM | 6.1 | 0.6% | Dec 5, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field ... |
| CVE-2022-35260 | MEDIUM | 6.5 | 1.8% | Dec 5, 2022 | curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white sp... |
| CVE-2022-35256 | MEDIUM | 6.5 | 2.6% | Dec 5, 2022 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated wit... |
| CVE-2022-23143 | MEDIUM | 6.5 | 0.6% | Dec 5, 2022 | ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an a... |
| CVE-2022-42706 | MEDIUM | 4.9 | 1.1% | Dec 5, 2022 | An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified throu... |
| CVE-2022-42705 | MEDIUM | 6.5 | 1.2% | Dec 5, 2022 | A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remo... |
| CVE-2022-43097 | MEDIUM | 5.4 | 0.5% | Dec 5, 2022 | Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scriptin... |
| CVE-2022-23467 | MEDIUM | 4.6 | 0.4% | Dec 5, 2022 | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu... |
| CVE-2022-4293 | MEDIUM | 5.5 | 0.5% | Dec 5, 2022 | Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. |
| CVE-2022-3926 | MEDIUM | 6.5 | 0.3% | Dec 5, 2022 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secr... |
| CVE-2022-3909 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-3892 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which ... |
| CVE-2022-3838 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The WPUpper Share Buttons WordPress plugin through 3.42 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-3837 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The Uji Countdown WordPress plugin before 2.3.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-3830 | MEDIUM | 4.8 | 0.5% | Dec 5, 2022 | The WP Page Builder WordPress plugin through 1.2.8 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2022-3677 | MEDIUM | 6.5 | 0.4% | Dec 5, 2022 | The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which... |
| CVE-2022-3426 | MEDIUM | 4.8 | 0.6% | Dec 5, 2022 | The Advanced WP Columns WordPress plugin through 2.0.6 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-4269 | MEDIUM | 5.5 | 0.2% | Dec 5, 2022 | A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirect... |
| CVE-2022-45478 | MEDIUM | 5.9 | 0.3% | Dec 5, 2022 | Telepad allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (... |
| CVE-2022-32634 | MEDIUM | 6.7 | 0.1% | Dec 5, 2022 | In ccci, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o... |
| CVE-2022-32633 | MEDIUM | 6.7 | 0.1% | Dec 5, 2022 | In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privi... |
| CVE-2022-32632 | MEDIUM | 6.7 | 0.1% | Dec 5, 2022 | In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation ... |
| CVE-2022-32631 | MEDIUM | 6.7 | 0.1% | Dec 5, 2022 | In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation ... |
| CVE-2022-32630 | MEDIUM | 6.7 | 0.1% | Dec 5, 2022 | In throttling, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now