2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41433 | MEDIUM | 4.8 | 0.4% | Nov 8, 2022 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ... |
| CVE-2022-41432 | MEDIUM | 4.8 | 0.4% | Nov 8, 2022 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ... |
| CVE-2022-43046 | MEDIUM | 4.8 | 0.5% | Nov 7, 2022 | Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the compone... |
| CVE-2022-44746 | MEDIUM | 5.5 | 0.1% | Nov 7, 2022 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ... |
| CVE-2022-44745 | MEDIUM | 5.5 | 0.1% | Nov 7, 2022 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Wi... |
| CVE-2022-38164 | MEDIUM | 6.5 | 0.4% | Nov 7, 2022 | A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could ... |
| CVE-2022-43351 | MEDIUM | 6.5 | 0.8% | Nov 7, 2022 | Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component... |
| CVE-2022-43317 | MEDIUM | 6.1 | 0.5% | Nov 7, 2022 | A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attacke... |
| CVE-2022-2188 | MEDIUM | 5.5 | 0.1% | Nov 7, 2022 | Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated priv... |
| CVE-2022-3873 | MEDIUM | 6.1 | 0.6% | Nov 7, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2. |
| CVE-2022-3489 | MEDIUM | 5.3 | 0.3% | Nov 7, 2022 | The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom... |
| CVE-2022-3462 | MEDIUM | 4.8 | 0.5% | Nov 7, 2022 | The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-3451 | MEDIUM | 4.3 | 0.3% | Nov 7, 2022 | The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple A... |
| CVE-2022-2387 | MEDIUM | 4.3 | 0.3% | Nov 7, 2022 | The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, ... |
| CVE-2022-44795 | MEDIUM | 6.5 | 0.5% | Nov 7, 2022 | An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lea... |
| CVE-2022-44793 | MEDIUM | 6.5 | 53.5% | Nov 7, 2022 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Excepti... |
| CVE-2022-44792 | MEDIUM | 6.5 | 52.1% | Nov 7, 2022 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug... |
| CVE-2022-3869 | MEDIUM | 6.1 | 1.3% | Nov 5, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2. |
| CVE-2022-43572 | MEDIUM | 6.5 | 0.8% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S... |
| CVE-2022-43570 | MEDIUM | 6.5 | 0.7% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup lan... |
| CVE-2022-43569 | MEDIUM | 5.4 | 0.7% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scrip... |
| CVE-2022-43568 | MEDIUM | 6.1 | 42.8% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via Jav... |
| CVE-2022-43564 | MEDIUM | 6.5 | 0.8% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule se... |
| CVE-2022-43562 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th... |
| CVE-2022-39384 | MEDIUM | 5.6 | 0.5% | Nov 4, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initial... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now