2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39026 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote at... |
| CVE-2022-39025 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attack... |
| CVE-2022-39024 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker c... |
| CVE-2022-39023 | MEDIUM | 6.5 | 0.9% | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e... |
| CVE-2022-39022 | MEDIUM | 6.5 | 0.9% | Oct 31, 2022 | U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e... |
| CVE-2022-39021 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vu... |
| CVE-2022-44034 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resu... |
| CVE-2022-44033 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resu... |
| CVE-2022-44032 | MEDIUM | 6.4 | 0.3% | Oct 30, 2022 | An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resu... |
| CVE-2022-44023 | MEDIUM | 5.3 | 0.7% | Oct 30, 2022 | PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response message... |
| CVE-2022-44022 | MEDIUM | 5.3 | 0.7% | Oct 30, 2022 | PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings fo... |
| CVE-2022-44020 | MEDIUM | 5.5 | 0.2% | Oct 30, 2022 | An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device c... |
| CVE-2022-43283 | MEDIUM | 5.5 | 0.3% | Oct 28, 2022 | wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. |
| CVE-2022-3402 | MEDIUM | 6.1 | 0.6% | Oct 28, 2022 | The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in vers... |
| CVE-2022-3228 | MEDIUM | 6.5 | 0.3% | Oct 28, 2022 | Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing... |
| CVE-2022-43170 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_con... |
| CVE-2022-43169 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/use... |
| CVE-2022-43167 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_aler... |
| CVE-2022-43166 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) o... |
| CVE-2022-43165 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) o... |
| CVE-2022-43164 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of ... |
| CVE-2022-3400 | MEDIUM | 6.5 | 0.6% | Oct 28, 2022 | The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav... |
| CVE-2022-39367 | MEDIUM | 6.5 | 1.0% | Oct 28, 2022 | QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine a... |
| CVE-2022-37424 | MEDIUM | 6.5 | 0.7% | Oct 28, 2022 | Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. |
| CVE-2022-3018 | MEDIUM | 4.9 | 0.7% | Oct 28, 2022 | An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now