2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43512MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-41696MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-45636HIGH8.1An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) with...
CVE-2022-38458MEDIUM5.9A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8...
CVE-2022-38452HIGH8.8A command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8....
CVE-2022-37337HIGH8.8A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A sp...
CVE-2022-36429HIGH7.2A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS7...
CVE-2022-45637CRITICAL9.8An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via ins...
CVE-2022-45635HIGH7.5An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensi...
CVE-2022-42334MEDIUM6.5x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains wh...
CVE-2022-42333HIGH8.6x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains wh...
CVE-2022-42332HIGH7.8x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but H...
CVE-2022-42331MEDIUM5.5x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security ...
CVE-2022-42485MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <=...
CVE-2022-41831MEDIUM5.4Auth. (contributor+) Cross-Site Scripting vulnerability in TCBarrett WP Glossary plugin <= 3.1.2 versions.
CVE-2022-41785MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions...
CVE-2022-45124HIGH7.5An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.0...
CVE-2022-43663CRITICAL9.8An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.0...
CVE-2022-4148MEDIUM4.3The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when ...
CVE-2022-3894MEDIUM4.3The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client...
CVE-2022-47591MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Mickael Austoni Map Multi Marker plugin <= 3.2.1 versions.
CVE-2022-47592MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions.
CVE-2022-4933CRITICAL9.8A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice u...
CVE-2022-48425HIGH7.8In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before r...
CVE-2022-48424HIGH7.8In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate the attribute name offset. An unhandled page fault ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now