2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43295 | MEDIUM | 5.5 | 0.3% | Nov 14, 2022 | XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795. |
| CVE-2022-41913 | MEDIUM | 5.4 | 0.4% | Nov 14, 2022 | Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar ... |
| CVE-2022-3903 | MEDIUM | 4.6 | 0.5% | Nov 14, 2022 | An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs w... |
| CVE-2022-39385 | MEDIUM | 6.5 | 0.5% | Nov 14, 2022 | Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a ... |
| CVE-2022-38167 | MEDIUM | 6.1 | 0.4% | Nov 14, 2022 | The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS. |
| CVE-2022-44390 | MEDIUM | 5.4 | 0.3% | Nov 14, 2022 | A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts ... |
| CVE-2022-44389 | MEDIUM | 6.5 | 0.2% | Nov 14, 2022 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module.... |
| CVE-2022-34317 | MEDIUM | 5.4 | 0.5% | Nov 14, 2022 | IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2022-43694 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image m... |
| CVE-2022-43692 | MEDIUM | 6.1 | 0.6% | Nov 14, 2022 | Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS - user can cau... |
| CVE-2022-34316 | MEDIUM | 5.3 | 0.6% | Nov 14, 2022 | IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used b... |
| CVE-2022-34315 | MEDIUM | 5.4 | 0.5% | Nov 14, 2022 | IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2022-38705 | MEDIUM | 6.1 | 0.7% | Nov 14, 2022 | IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a rever... |
| CVE-2022-34329 | MEDIUM | 5.3 | 0.7% | Nov 14, 2022 | IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 22... |
| CVE-2022-0137 | MEDIUM | 5.5 | 0.6% | Nov 14, 2022 | A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffe... |
| CVE-2022-3992 | MEDIUM | 6.1 | 0.5% | Nov 14, 2022 | A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this v... |
| CVE-2022-35719 | MEDIUM | 5.5 | 0.2% | Nov 14, 2022 | IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be ... |
| CVE-2022-43342 | MEDIUM | 5.4 | 0.5% | Nov 14, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to ... |
| CVE-2022-3632 | MEDIUM | 6.5 | 0.3% | Nov 14, 2022 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could ... |
| CVE-2022-3631 | MEDIUM | 4.8 | 0.5% | Nov 14, 2022 | The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, wh... |
| CVE-2022-3578 | MEDIUM | 6.1 | 0.9% | Nov 14, 2022 | The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the ... |
| CVE-2022-3539 | MEDIUM | 4.8 | 0.5% | Nov 14, 2022 | The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and es... |
| CVE-2022-3538 | MEDIUM | 6.5 | 0.3% | Nov 14, 2022 | The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling... |
| CVE-2022-3484 | MEDIUM | 6.1 | 0.9% | Nov 14, 2022 | The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leadi... |
| CVE-2022-3469 | MEDIUM | 4.8 | 0.5% | Nov 14, 2022 | The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow h... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now