2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45473 | MEDIUM | 5.5 | 0.3% | Nov 18, 2022 | In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666. |
| CVE-2022-24038 | MEDIUM | 6.5 | 0.6% | Nov 18, 2022 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated ... |
| CVE-2022-24939 | MEDIUM | 6.5 | 0.3% | Nov 18, 2022 | A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This ca... |
| CVE-2022-45375 | MEDIUM | 5.4 | 0.4% | Nov 17, 2022 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in iFeature Slider plugin <= 1.2 on WordPress. |
| CVE-2022-44736 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Chameleon plugin <= 1.4.3 on WordPress. |
| CVE-2022-44591 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Anthologize plugin <= 0.8.0 on WordPress. |
| CVE-2022-43332 | MEDIUM | 6.1 | 0.6% | Nov 17, 2022 | A cross-site scripting (XSS) vulnerability in Wondercms v3.3.4 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2022-43171 | MEDIUM | 6.5 | 0.7% | Nov 17, 2022 | A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows att... |
| CVE-2022-43096 | MEDIUM | 6.8 | 0.5% | Nov 17, 2022 | Mediatrix 4102 before v48.5.2718 allows local attackers to gain root access via the UART port. |
| CVE-2022-41315 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Ezoic plugin <= 2.8.8 on WordPress. |
| CVE-2022-41132 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | Unauthenticated Plugin Settings Change Leading To Stored XSS Vulnerability in Ezoic plugin <= 2.8.8 on WordPress. |
| CVE-2022-40694 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress. |
| CVE-2022-39181 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The s... |
| CVE-2022-39178 | MEDIUM | 5.3 | 0.6% | Nov 17, 2022 | Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. I... |
| CVE-2022-36357 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions. |
| CVE-2022-20460 | MEDIUM | 6.7 | 0.1% | Nov 17, 2022 | In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. ... |
| CVE-2022-20459 | MEDIUM | 6.7 | 0.1% | Nov 17, 2022 | In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead ... |
| CVE-2022-20428 | MEDIUM | 6.7 | 0.1% | Nov 17, 2022 | In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escal... |
| CVE-2022-20427 | MEDIUM | 6.7 | 0.1% | Nov 17, 2022 | In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local ... |
| CVE-2022-45072 | MEDIUM | 4.3 | 0.3% | Nov 17, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress. |
| CVE-2022-43192 | MEDIUM | 6.7 | 0.3% | Nov 17, 2022 | An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attacke... |
| CVE-2022-3090 | MEDIUM | 5.3 | 0.6% | Nov 17, 2022 | Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versi... |
| CVE-2022-39389 | MEDIUM | 6.5 | 1.0% | Nov 17, 2022 | Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before ve... |
| CVE-2022-38461 | MEDIUM | 4.3 | 0.5% | Nov 17, 2022 | Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a s... |
| CVE-2022-43142 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows atta... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now