2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42127 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not prop... |
| CVE-2022-42126 | MEDIUM | 4.3 | 0.8% | Nov 15, 2022 | The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 be... |
| CVE-2022-42119 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Port... |
| CVE-2022-42118 | MEDIUM | 6.1 | 1.1% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Lifera... |
| CVE-2022-42111 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4... |
| CVE-2022-42110 | MEDIUM | 6.1 | 0.6% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Lifera... |
| CVE-2022-33986 | MEDIUM | 6.4 | 0.1% | Nov 15, 2022 | DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. D... |
| CVE-2022-33906 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMR... |
| CVE-2022-32267 | MEDIUM | 6.4 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM c... |
| CVE-2022-31243 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used... |
| CVE-2022-30774 | MEDIUM | 6.4 | 0.2% | Nov 15, 2022 | DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been... |
| CVE-2022-43695 | MEDIUM | 4.8 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2022-43691 | MEDIUM | 5.3 | 0.4% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive ... |
| CVE-2022-43690 | MEDIUM | 6.3 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_... |
| CVE-2022-43689 | MEDIUM | 5.3 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leadi... |
| CVE-2022-43688 | MEDIUM | 4.8 | 0.5% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2022-43687 | MEDIUM | 5.4 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successf... |
| CVE-2022-40903 | MEDIUM | 6.5 | 0.3% | Nov 14, 2022 | Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access at... |
| CVE-2022-33982 | MEDIUM | 6.4 | 0.2% | Nov 14, 2022 | DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on th... |
| CVE-2022-33907 | MEDIUM | 6.4 | 0.2% | Nov 14, 2022 | DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver coul... |
| CVE-2022-43968 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboa... |
| CVE-2022-43967 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multili... |
| CVE-2022-43686 | MEDIUM | 6.5 | 1.0% | Nov 14, 2022 | In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can b... |
| CVE-2022-32266 | MEDIUM | 6.4 | 0.2% | Nov 14, 2022 | DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU a... |
| CVE-2022-30773 | MEDIUM | 6.4 | 0.1% | Nov 14, 2022 | DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have be... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now