2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25275 | HIGH | 7.5 | 0.7% | Apr 26, 2023 | In some situations, the Image module does not correctly check access to image files not stored in the standard public fi... |
| CVE-2022-25274 | MEDIUM | 5.4 | 0.4% | Apr 26, 2023 | Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated... |
| CVE-2022-25273 | HIGH | 7.5 | 0.6% | Apr 26, 2023 | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro... |
| CVE-2022-41739 | HIGH | 8.4 | 0.2% | Apr 26, 2023 | IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs ru... |
| CVE-2022-36769 | HIGH | 7.2 | 0.9% | Apr 26, 2023 | IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can ... |
| CVE-2022-45291 | HIGH | 7.2 | 1.3% | Apr 25, 2023 | PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by inje... |
| CVE-2022-40725 | MEDIUM | 6.1 | 0.2% | Apr 25, 2023 | PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the m... |
| CVE-2022-40724 | HIGH | 8.8 | 0.2% | Apr 25, 2023 | The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF... |
| CVE-2022-40723 | MEDIUM | 6.5 | 0.5% | Apr 25, 2023 | The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to M... |
| CVE-2022-40722 | MEDIUM | 5.8 | 0.3% | Apr 25, 2023 | A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID ... |
| CVE-2022-40482 | MEDIUM | 5.3 | 0.9% | Apr 25, 2023 | The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration v... |
| CVE-2022-23721 | LOW | 3.3 | 0.2% | Apr 25, 2023 | PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username coll... |
| CVE-2022-47608 | MEDIUM | 4.8 | 0.4% | Apr 25, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 version... |
| CVE-2022-31244 | HIGH | 7.8 | 0.3% | Apr 25, 2023 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. |
| CVE-2022-42335 | HIGH | 7.8 | 0.3% | Apr 25, 2023 | x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but... |
| CVE-2022-45837 | MEDIUM | 6.1 | 0.4% | Apr 25, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in Denis 微信机器人高级版 plugin <= 6.0.1 versions. |
| CVE-2022-28354 | MEDIUM | 6.1 | 0.5% | Apr 24, 2023 | In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a ti... |
| CVE-2022-41612 | MEDIUM | 4.8 | 0.4% | Apr 24, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shareaholic Similar Posts plugin <= 3.1.6 versions. |
| CVE-2022-47598 | MEDIUM | 4.8 | 0.4% | Apr 24, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup plugin <= 1.1.2 versions... |
| CVE-2022-47158 | MEDIUM | 4.8 | 0.4% | Apr 24, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pakpobox alfred24 Click & Collect plugin <= 1.1.7 vers... |
| CVE-2022-45084 | MEDIUM | 6.1 | 0.4% | Apr 24, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions. |
| CVE-2022-48477 | CRITICAL | 9.8 | 0.5% | Apr 24, 2023 | In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing |
| CVE-2022-48476 | HIGH | 7.5 | 0.8% | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible |
| CVE-2022-45080 | HIGH | 8.8 | 0.3% | Apr 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions. |
| CVE-2022-45074 | HIGH | 8.8 | 0.3% | Apr 23, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For B... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now