2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25275HIGH7.5In some situations, the Image module does not correctly check access to image files not stored in the standard public fi...
CVE-2022-25274MEDIUM5.4Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated...
CVE-2022-25273HIGH7.5Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro...
CVE-2022-41739HIGH8.4 IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs ru...
CVE-2022-36769HIGH7.2 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can ...
CVE-2022-45291HIGH7.2PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by inje...
CVE-2022-40725MEDIUM6.1PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the m...
CVE-2022-40724HIGH8.8The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF...
CVE-2022-40723MEDIUM6.5The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to M...
CVE-2022-40722MEDIUM5.8A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID ...
CVE-2022-40482MEDIUM5.3The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration v...
CVE-2022-23721LOW3.3PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username coll...
CVE-2022-47608MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 version...
CVE-2022-31244HIGH7.8Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
CVE-2022-42335HIGH7.8x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but...
CVE-2022-45837MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Denis 微信机器人高级版 plugin <= 6.0.1 versions.
CVE-2022-28354MEDIUM6.1In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a ti...
CVE-2022-41612MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shareaholic Similar Posts plugin <= 3.1.6 versions.
CVE-2022-47598MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup plugin <= 1.1.2 versions...
CVE-2022-47158MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pakpobox alfred24 Click & Collect plugin <= 1.1.7 vers...
CVE-2022-45084MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
CVE-2022-48477CRITICAL9.8In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
CVE-2022-48476HIGH7.5In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-45080HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.
CVE-2022-45074HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For B...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now