2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4308 | HIGH | 8.8 | 0.2% | Apr 19, 2023 | Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteMan... |
| CVE-2022-38125 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu... |
| CVE-2022-2507 | MEDIUM | 5.3 | 0.4% | Apr 19, 2023 | In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage |
| CVE-2022-43378 | MEDIUM | 6.5 | 0.5% | Apr 18, 2023 | A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user t... |
| CVE-2022-43377 | HIGH | 7.5 | 0.6% | Apr 18, 2023 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account ... |
| CVE-2022-43376 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists t... |
| CVE-2022-34755 | MEDIUM | 6.7 | 0.2% | Apr 18, 2023 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged ... |
| CVE-2022-45836 | MEDIUM | 6.1 | 0.7% | Apr 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. |
| CVE-2022-44632 | MEDIUM | 4.8 | 0.4% | Apr 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified ... |
| CVE-2022-46640 | CRITICAL | 9.8 | 2.4% | Apr 18, 2023 | Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a ... |
| CVE-2022-45839 | MEDIUM | 5.4 | 0.4% | Apr 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions. |
| CVE-2022-45838 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versi... |
| CVE-2022-44735 | MEDIUM | 4.8 | 0.4% | Apr 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions. |
| CVE-2022-46389 | MEDIUM | 6.1 | 0.6% | Apr 17, 2023 | There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11... |
| CVE-2022-44726 | MEDIUM | 5.4 | 0.4% | Apr 17, 2023 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. |
| CVE-2022-45849 | MEDIUM | 5.4 | 0.5% | Apr 16, 2023 | Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions. |
| CVE-2022-44734 | MEDIUM | 4.8 | 0.4% | Apr 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 ... |
| CVE-2022-43480 | MEDIUM | 4.8 | 0.4% | Apr 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versi... |
| CVE-2022-43458 | MEDIUM | 5.4 | 0.4% | Apr 16, 2023 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 ve... |
| CVE-2022-48314 | MEDIUM | 6.5 | 0.2% | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat... |
| CVE-2022-48313 | MEDIUM | 6.5 | 0.2% | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat... |
| CVE-2022-48312 | CRITICAL | 9.1 | 0.4% | Apr 16, 2023 | The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability m... |
| CVE-2022-34128 | CRITICAL | 9.8 | 7.7% | Apr 16, 2023 | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data ... |
| CVE-2022-34127 | HIGH | 7.5 | 6.7% | Apr 16, 2023 | The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.p... |
| CVE-2022-34126 | HIGH | 7.5 | 1.2% | Apr 16, 2023 | The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php f... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now