2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38388 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to imp... |
| CVE-2022-32175 | MEDIUM | 5.4 | 0.3% | Oct 11, 2022 | In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom ... |
| CVE-2022-33749 | MEDIUM | 5.3 | 0.9% | Oct 11, 2022 | XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descr... |
| CVE-2022-33748 | MEDIUM | 5.6 | 0.2% | Oct 11, 2022 | lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an erro... |
| CVE-2022-33746 | MEDIUM | 6.5 | 0.3% | Oct 11, 2022 | P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of si... |
| CVE-2022-40631 | MEDIUM | 6.1 | 0.4% | Oct 11, 2022 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT (All versions ... |
| CVE-2022-40180 | MEDIUM | 5.3 | 0.2% | Oct 11, 2022 | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ... |
| CVE-2022-40178 | MEDIUM | 5.4 | 0.5% | Oct 11, 2022 | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ... |
| CVE-2022-40177 | MEDIUM | 5.7 | 0.8% | Oct 11, 2022 | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ... |
| CVE-2022-36363 | MEDIUM | 5.3 | 0.4% | Oct 11, 2022 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0... |
| CVE-2022-3433 | MEDIUM | 6.5 | 0.7% | Oct 10, 2022 | The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a h... |
| CVE-2022-41748 | MEDIUM | 6.7 | 0.2% | Oct 10, 2022 | A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a... |
| CVE-2022-3220 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privile... |
| CVE-2022-3209 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_sl... |
| CVE-2022-3208 | MEDIUM | 6.5 | 0.3% | Oct 10, 2022 | The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make... |
| CVE-2022-3207 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-3137 | MEDIUM | 5.4 | 0.5% | Oct 10, 2022 | The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any a... |
| CVE-2022-3136 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-34402 | MEDIUM | 4.9 | 0.6% | Oct 10, 2022 | Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker c... |
| CVE-2022-34334 | MEDIUM | 6.5 | 0.3% | Oct 10, 2022 | IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated ... |
| CVE-2022-2981 | MEDIUM | 4.9 | 0.9% | Oct 10, 2022 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold... |
| CVE-2022-2891 | MEDIUM | 5.9 | 0.7% | Oct 10, 2022 | The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could b... |
| CVE-2022-2823 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its ... |
| CVE-2022-2629 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in fr... |
| CVE-2022-2554 | MEDIUM | 4.9 | 0.8% | Oct 10, 2022 | The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now