2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38388MEDIUM5.5IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive information due to imp...
CVE-2022-32175MEDIUM5.4In AdGuardHome, versions v0.95 through v0.108.0-b.13 are vulnerable to Cross-Site Request Forgery (CSRF), in the custom ...
CVE-2022-33749MEDIUM5.3XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descr...
CVE-2022-33748MEDIUM5.6lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an erro...
CVE-2022-33746MEDIUM6.5P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of si...
CVE-2022-40631MEDIUM6.1A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT (All versions ...
CVE-2022-40180MEDIUM5.3A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ...
CVE-2022-40178MEDIUM5.4A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ...
CVE-2022-40177MEDIUM5.7A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < ...
CVE-2022-36363MEDIUM5.3A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2022-3433MEDIUM6.5The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a h...
CVE-2022-41748MEDIUM6.7A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a...
CVE-2022-3220MEDIUM4.8The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privile...
CVE-2022-3209MEDIUM6.1The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_sl...
CVE-2022-3208MEDIUM6.5The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make...
CVE-2022-3207MEDIUM4.8The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow...
CVE-2022-3137MEDIUM5.4The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any a...
CVE-2022-3136MEDIUM4.8The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-34402MEDIUM4.9Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker c...
CVE-2022-34334MEDIUM6.5IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated ...
CVE-2022-2981MEDIUM4.9The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold...
CVE-2022-2891MEDIUM5.9The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could b...
CVE-2022-2823MEDIUM4.8The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its ...
CVE-2022-2629MEDIUM4.8The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in fr...
CVE-2022-2554MEDIUM4.9The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now