2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41333 | HIGH | 7.5 | 7.2% | Mar 7, 2023 | An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below ... |
| CVE-2022-41329 | MEDIUM | 5.3 | 0.6% | Mar 7, 2023 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2... |
| CVE-2022-41328 | HIGH | 7.1 | 12.3% | Mar 7, 2023 | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet Fort... |
| CVE-2022-40676 | MEDIUM | 5.4 | 0.5% | Mar 7, 2023 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4... |
| CVE-2022-39953 | HIGH | 7.8 | 0.2% | Mar 7, 2023 | A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, ... |
| CVE-2022-39951 | HIGH | 8.8 | 1.8% | Mar 7, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2022-27490 | MEDIUM | 6.5 | 0.5% | Mar 7, 2023 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, Forti... |
| CVE-2022-22297 | MEDIUM | 5.5 | 0.2% | Mar 7, 2023 | An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpr... |
| CVE-2022-4932 | MEDIUM | 4.3 | 0.6% | Mar 7, 2023 | The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. ... |
| CVE-2022-4931 | MEDIUM | 4.3 | 0.5% | Mar 7, 2023 | The BackupWordPress plugin for WordPress is vulnerable to information disclosure in versions up to, and including 3.12. ... |
| CVE-2022-3760 | CRITICAL | 9.8 | 0.6% | Mar 7, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia... |
| CVE-2022-4904 | HIGH | 8.6 | 1.2% | Mar 6, 2023 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, ... |
| CVE-2022-4134 | LOW | 2.8 | 0.3% | Mar 6, 2023 | A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, com... |
| CVE-2022-45142 | HIGH | 7.5 | 0.5% | Mar 6, 2023 | The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!=... |
| CVE-2022-45141 | CRITICAL | 9.8 | 0.5% | Mar 6, 2023 | Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and pe... |
| CVE-2022-3857 | — | — | — | Mar 6, 2023 | Rejected reason: Maintainer contacted. This is a false-positive. The flaw does not actually exist and was erroneously te... |
| CVE-2022-3854 | MEDIUM | 6.5 | 0.6% | Mar 6, 2023 | A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by ... |
| CVE-2022-3707 | MEDIUM | 5.5 | 0.2% | Mar 6, 2023 | A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resour... |
| CVE-2022-3424 | HIGH | 7.8 | 0.2% | Mar 6, 2023 | A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl functi... |
| CVE-2022-3277 | MEDIUM | 6.5 | 1.1% | Mar 6, 2023 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user t... |
| CVE-2022-42248 | MEDIUM | 5.4 | 0.4% | Mar 6, 2023 | QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functi... |
| CVE-2022-4930 | MEDIUM | 5.4 | 0.5% | Mar 6, 2023 | A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an... |
| CVE-2022-4328 | CRITICAL | 9.8 | 4.4% | Mar 6, 2023 | The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could ... |
| CVE-2022-4265 | HIGH | 8.8 | 0.5% | Mar 6, 2023 | The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiatin... |
| CVE-2022-48364 | MEDIUM | 4.3 | 0.7% | Mar 6, 2023 | The undo_mark_statuses_as_sensitive method in app/services/approve_appeal_service.rb in Mastodon 3.5.x before 3.5.3 does... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now