2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-45473MEDIUM5.5In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666.
CVE-2022-24038MEDIUM6.5Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated ...
CVE-2022-24939MEDIUM6.5  A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This ca...
CVE-2022-45375MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress.
CVE-2022-44736MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress.
CVE-2022-44591MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress.
CVE-2022-43332MEDIUM6.1A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML...
CVE-2022-43171MEDIUM6.5A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows att...
CVE-2022-43096MEDIUM6.8Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port.
CVE-2022-41315MEDIUM4.8Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
CVE-2022-41132MEDIUM6.1Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress.
CVE-2022-40694MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.
CVE-2022-39181MEDIUM6.1 GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The s...
CVE-2022-39178MEDIUM5.3 Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. I...
CVE-2022-36357MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
CVE-2022-20460MEDIUM6.7In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. ...
CVE-2022-20459MEDIUM6.7In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead ...
CVE-2022-20428MEDIUM6.7In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escal...
CVE-2022-20427MEDIUM6.7In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local ...
CVE-2022-45072MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
CVE-2022-43192MEDIUM6.7An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attacke...
CVE-2022-3090MEDIUM5.3Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versi...
CVE-2022-39389MEDIUM6.5Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before ve...
CVE-2022-38461MEDIUM4.3Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a s...
CVE-2022-43142MEDIUM6.1A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows atta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now