2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41333HIGH7.5An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below ...
CVE-2022-41329MEDIUM5.3An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2...
CVE-2022-41328HIGH7.1A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet Fort...
CVE-2022-40676MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4...
CVE-2022-39953HIGH7.8A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, ...
CVE-2022-39951HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2022-27490MEDIUM6.5A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, Forti...
CVE-2022-22297MEDIUM5.5An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr...
CVE-2022-4932MEDIUM4.3The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. ...
CVE-2022-4931MEDIUM4.3The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. ...
CVE-2022-3760CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia...
CVE-2022-4904HIGH8.6A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, ...
CVE-2022-4134LOW2.8A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, com...
CVE-2022-45142HIGH7.5The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!=...
CVE-2022-45141CRITICAL9.8Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and pe...
CVE-2022-3857Rejected reason: Maintainer contacted. This is a false-positive. The flaw does not actually exist and was erroneously te...
CVE-2022-3854MEDIUM6.5A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by ...
CVE-2022-3707MEDIUM5.5A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resour...
CVE-2022-3424HIGH7.8A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl functi...
CVE-2022-3277MEDIUM6.5An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user t...
CVE-2022-42248MEDIUM5.4QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functi...
CVE-2022-4930MEDIUM5.4A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an...
CVE-2022-4328CRITICAL9.8The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could ...
CVE-2022-4265HIGH8.8The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiatin...
CVE-2022-48364MEDIUM4.3The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now