2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2448 | MEDIUM | 4.8 | 0.5% | Oct 10, 2022 | The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2022-2350 | MEDIUM | 5.3 | 0.4% | Oct 10, 2022 | The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its sett... |
| CVE-2022-20944 | MEDIUM | 6.8 | 0.2% | Oct 10, 2022 | A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series... |
| CVE-2022-20864 | MEDIUM | 4.6 | 0.3% | Oct 10, 2022 | A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalys... |
| CVE-2022-20830 | MEDIUM | 5.3 | 0.7% | Oct 10, 2022 | A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis... |
| CVE-2022-40257 | MEDIUM | 5.4 | 0.4% | Oct 10, 2022 | An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a... |
| CVE-2022-40248 | MEDIUM | 5.4 | 0.4% | Oct 10, 2022 | An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a... |
| CVE-2022-3442 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unkno... |
| CVE-2022-26121 | MEDIUM | 5.3 | 0.7% | Oct 10, 2022 | An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.... |
| CVE-2022-3438 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
| CVE-2022-42724 | MEDIUM | 4.3 | 0.4% | Oct 10, 2022 | app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information t... |
| CVE-2022-42012 | MEDIUM | 6.5 | 1.3% | Oct 10, 2022 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic... |
| CVE-2022-42011 | MEDIUM | 6.5 | 1.3% | Oct 10, 2022 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic... |
| CVE-2022-42010 | MEDIUM | 6.5 | 0.8% | Oct 10, 2022 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic... |
| CVE-2022-42703 | MEDIUM | 5.5 | 1.0% | Oct 9, 2022 | mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse. |
| CVE-2022-3435 | MEDIUM | 4.3 | 3.7% | Oct 8, 2022 | A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the ... |
| CVE-2022-3434 | MEDIUM | 5.4 | 0.5% | Oct 8, 2022 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affect... |
| CVE-2022-39281 | MEDIUM | 6.5 | 1.4% | Oct 8, 2022 | fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0.... |
| CVE-2022-41442 | MEDIUM | 6.1 | 0.4% | Oct 7, 2022 | PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function ... |
| CVE-2022-39291 | MEDIUM | 5.4 | 5.1% | Oct 7, 2022 | ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are su... |
| CVE-2022-39290 | MEDIUM | 6.5 | 5.4% | Oct 7, 2022 | ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated use... |
| CVE-2022-39285 | MEDIUM | 5.4 | 3.7% | Oct 7, 2022 | ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a c... |
| CVE-2022-31681 | MEDIUM | 6.5 | 0.2% | Oct 7, 2022 | VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process on... |
| CVE-2022-39287 | MEDIUM | 6.5 | 0.4% | Oct 7, 2022 | tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were ... |
| CVE-2022-32593 | MEDIUM | 6.7 | 0.1% | Oct 7, 2022 | In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now