2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34410 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A ... |
| CVE-2022-34409 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A ... |
| CVE-2022-34408 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A ... |
| CVE-2022-34407 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A ... |
| CVE-2022-34406 | MEDIUM | 6.7 | 0.2% | Mar 16, 2023 | Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A ... |
| CVE-2022-41554 | MEDIUM | 5.4 | 0.4% | Mar 16, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. |
| CVE-2022-40699 | MEDIUM | 6.1 | 0.4% | Mar 16, 2023 | Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. |
| CVE-2022-38971 | MEDIUM | 5.4 | 0.4% | Mar 16, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Prof... |
| CVE-2022-38063 | HIGH | 8.8 | 0.3% | Mar 16, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Social Login WP plugin <= 5.0.0.0 versions. |
| CVE-2022-4009 | HIGH | 8.8 | 0.7% | Mar 16, 2023 | In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation |
| CVE-2022-4313 | HIGH | 8.8 | 1.2% | Mar 15, 2023 | A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that... |
| CVE-2022-46773 | MEDIUM | 6.5 | 0.5% | Mar 15, 2023 | IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential ... |
| CVE-2022-46774 | MEDIUM | 6.5 | 0.3% | Mar 15, 2023 | IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permission... |
| CVE-2022-43874 | MEDIUM | 6.1 | 0.4% | Mar 15, 2023 | IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-si... |
| CVE-2022-37402 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions. |
| CVE-2022-44580 | HIGH | 8.8 | 0.6% | Mar 15, 2023 | SQL Injection (SQLi) vulnerability in RichPlugins Plugin for Google Reviews plugin <= 2.2.3 versions. |
| CVE-2022-38456 | HIGH | 7.5 | 0.6% | Mar 15, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ernest Marcinko Ajax Search Lite plugin <= 4... |
| CVE-2022-34148 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBacku... |
| CVE-2022-45155 | MEDIUM | 5.5 | 0.2% | Mar 15, 2023 | An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attack... |
| CVE-2022-47427 | HIGH | 8.8 | 0.3% | Mar 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. |
| CVE-2022-39216 | CRITICAL | 9.8 | 0.9% | Mar 14, 2023 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset... |
| CVE-2022-39214 | HIGH | 7.5 | 25.6% | Mar 14, 2023 | Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, a user wh... |
| CVE-2022-46743 | — | — | — | Mar 14, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-3680 | — | — | — | Mar 14, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2022-3678 | — | — | — | Mar 14, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now