2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27912 | MEDIUM | 5.3 | 0.5% | Oct 25, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous ... |
| CVE-2022-3644 | MEDIUM | 5.5 | 0.3% | Oct 25, 2022 | The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes th... |
| CVE-2022-36454 | MEDIUM | 6.5 | 0.5% | Oct 25, 2022 | A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to ... |
| CVE-2022-3392 | MEDIUM | 4.8 | 0.6% | Oct 25, 2022 | The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-3391 | MEDIUM | 4.8 | 0.6% | Oct 25, 2022 | The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-3350 | MEDIUM | 4.8 | 0.5% | Oct 25, 2022 | The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could all... |
| CVE-2022-3344 | MEDIUM | 5.5 | 0.2% | Oct 25, 2022 | A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept th... |
| CVE-2022-3247 | MEDIUM | 6.5 | 0.7% | Oct 25, 2022 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJA... |
| CVE-2022-3097 | MEDIUM | 6.5 | 0.3% | Oct 25, 2022 | The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible f... |
| CVE-2022-39837 | MEDIUM | 5.5 | 0.4% | Oct 25, 2022 | An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi... |
| CVE-2022-39836 | MEDIUM | 5.5 | 0.4% | Oct 25, 2022 | An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi... |
| CVE-2022-39351 | MEDIUM | 4.4 | 0.2% | Oct 25, 2022 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software ... |
| CVE-2022-39350 | MEDIUM | 5.4 | 0.7% | Oct 25, 2022 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis... |
| CVE-2022-39349 | MEDIUM | 5.5 | 0.3% | Oct 25, 2022 | The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `Shar... |
| CVE-2022-39340 | MEDIUM | 5.3 | 0.7% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali... |
| CVE-2022-39315 | MEDIUM | 5.3 | 0.6% | Oct 25, 2022 | Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera... |
| CVE-2022-38200 | MEDIUM | 6.1 | 0.3% | Oct 25, 2022 | A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7... |
| CVE-2022-38199 | MEDIUM | 6.1 | 0.3% | Oct 25, 2022 | A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cas... |
| CVE-2022-38198 | MEDIUM | 6.1 | 0.5% | Oct 25, 2022 | There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below t... |
| CVE-2022-38197 | MEDIUM | 6.1 | 0.5% | Oct 25, 2022 | Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated... |
| CVE-2022-38195 | MEDIUM | 6.1 | 0.4% | Oct 25, 2022 | There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remot... |
| CVE-2022-36783 | MEDIUM | 5.4 | 0.4% | Oct 25, 2022 | AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter calle... |
| CVE-2022-35739 | MEDIUM | 5.3 | 0.7% | Oct 25, 2022 | PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to in... |
| CVE-2022-34870 | MEDIUM | 5.4 | 1.1% | Oct 25, 2022 | Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse we... |
| CVE-2022-33757 | MEDIUM | 6.5 | 0.8% | Oct 25, 2022 | An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privil... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now