2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41710 | MEDIUM | 5.5 | 0.4% | Nov 3, 2022 | Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp... |
| CVE-2022-40276 | MEDIUM | 5.5 | 0.4% | Nov 3, 2022 | Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to... |
| CVE-2022-40235 | MEDIUM | 6.5 | 0.6% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run j... |
| CVE-2022-40230 | MEDIUM | 6.5 | 0.4% | Nov 3, 2022 | "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an aut... |
| CVE-2022-40131 | MEDIUM | 4.3 | 0.2% | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an... |
| CVE-2022-38712 | MEDIUM | 5.9 | 0.5% | Nov 3, 2022 | "IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc... |
| CVE-2022-38710 | MEDIUM | 5.3 | 0.3% | Nov 3, 2022 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info... |
| CVE-2022-36428 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress. |
| CVE-2022-36404 | MEDIUM | 5.4 | 0.2% | Nov 3, 2022 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugi... |
| CVE-2022-35642 | MEDIUM | 5.4 | 0.4% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2022-35279 | MEDIUM | 4.3 | 0.3% | Nov 3, 2022 | "IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2... |
| CVE-2022-34339 | MEDIUM | 6.5 | 0.4% | Nov 3, 2022 | "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authent... |
| CVE-2022-30615 | MEDIUM | 5.4 | 0.4% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2022-22442 | MEDIUM | 6.5 | 0.5% | Nov 3, 2022 | "IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with... |
| CVE-2022-43372 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php. |
| CVE-2022-42753 | MEDIUM | 6.1 | 0.4% | Nov 3, 2022 | SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the ... |
| CVE-2022-3852 | MEDIUM | 6.5 | 0.5% | Nov 3, 2022 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3... |
| CVE-2022-3675 | MEDIUM | 5.5 | 0.2% | Nov 3, 2022 | Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requ... |
| CVE-2022-2696 | MEDIUM | 6.5 | 0.5% | Nov 3, 2022 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2022-39376 | MEDIUM | 6.5 | 0.5% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39375 | MEDIUM | 5.4 | 0.5% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39373 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39372 | MEDIUM | 5.4 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39371 | MEDIUM | 5.4 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
| CVE-2022-39370 | MEDIUM | 4.3 | 0.4% | Nov 3, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now