2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32471HIGH7An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the comman...
CVE-2022-29557HIGH8.8LexisNexis Firco Compliance Link 3.7 allows CSRF.
CVE-2022-41564MEDIUM6.5The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains ...
CVE-2022-22564MEDIUM5.9Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker...
CVE-2022-4286MEDIUM6.1 A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime ver...
CVE-2022-46862HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ExpressTech Quiz And Survey Master – Best Quiz, Exam and Survey Plugi...
CVE-2022-47977HIGH7.8A vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0). The ...
CVE-2022-47936HIGH7.8A vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Para...
CVE-2022-35868MEDIUM6.7A vulnerability has been identified in TIA Multiuser Server V14 (All versions), TIA Multiuser Server V15 (All versions <...
CVE-2022-31808HIGH7.8A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated AC...
CVE-2022-43469HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7...
CVE-2022-4138HIGH8.1A Cross Site Request Forgery issue has been discovered in GitLab CE/EE affecting all versions before 15.6.7, all version...
CVE-2022-3759HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 15.6.7, all versions start...
CVE-2022-3411MEDIUM6.5A lack of length validation in GitLab CE/EE affecting all versions from 12.4 before 15.6.7, 15.7 before 15.7.6, and 15.8...
CVE-2022-47034CRITICAL9.8A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass aut...
CVE-2022-4905MEDIUM6.1A vulnerability was found in UDX Stateless Media Plugin 3.1.1 on WordPress. It has been declared as problematic. This vu...
CVE-2022-45962MEDIUM6.5Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via Calendar...
CVE-2022-48110MEDIUM6.1CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK...
CVE-2022-45285MEDIUM6.1Vsourz Digital Advanced Contact form 7 DB Versions 1.7.2 and 1.9.1 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-48077HIGH7.8Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate priv...
CVE-2022-41134HIGH8.8Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plu...
CVE-2022-3089CRITICAL9.8 Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker...
CVE-2022-4830MEDIUM5.4The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes bef...
CVE-2022-4783MEDIUM5.4The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes b...
CVE-2022-4759MEDIUM5.4The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputt...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now