2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-36042HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to ...
CVE-2022-36039HIGH7.8Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.4.0 and prior are vulnerable to ...
CVE-2022-36038HIGH7.8CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code exe...
CVE-2022-31791HIGH7.8WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their p...
CVE-2022-3026HIGH8.8The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via th...
CVE-2022-35847HIGH8.8An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR managemen...
CVE-2022-32264HIGH7.5sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling ...
CVE-2022-31790HIGH7.5WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication serv...
CVE-2022-30298HIGH7.8An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al...
CVE-2022-2735HIGH7.8A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for i...
CVE-2022-2633HIGH8.2The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side reques...
CVE-2022-2542HIGH8.8The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in v...
CVE-2022-2541HIGH8.8The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers...
CVE-2022-2540HIGH8.8The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers...
CVE-2022-2442HIGH7.2The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via th...
CVE-2022-2438HIGH7.2The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' val...
CVE-2022-2436HIGH8.8The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]...
CVE-2022-2434HIGH8.8The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path...
CVE-2022-2433HIGH7.5The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input ...
CVE-2022-2431HIGH8.8The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2....
CVE-2022-2429HIGH8The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, an...
CVE-2022-2233HIGH8.8The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4....
CVE-2022-29058HIGH7.8An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line...
CVE-2022-28885HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ...
CVE-2022-28884HIGH7.5A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now