2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4577 | MEDIUM | 5.4 | 0.6% | Feb 6, 2023 | The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4489 | HIGH | 7.2 | 1.3% | Feb 6, 2023 | The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privil... |
| CVE-2022-4459 | MEDIUM | 5.4 | 0.7% | Feb 6, 2023 | The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before out... |
| CVE-2022-4384 | MEDIUM | 6.5 | 0.9% | Feb 6, 2023 | The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) fr... |
| CVE-2022-4321 | MEDIUM | 6.1 | 1.2% | Feb 6, 2023 | The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Refl... |
| CVE-2022-32663 | HIGH | 7.5 | 1.6% | Feb 6, 2023 | In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of s... |
| CVE-2022-32656 | MEDIUM | 6.7 | 0.3% | Feb 6, 2023 | In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala... |
| CVE-2022-32655 | MEDIUM | 6.7 | 0.3% | Feb 6, 2023 | In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala... |
| CVE-2022-32654 | MEDIUM | 6.7 | 0.3% | Feb 6, 2023 | In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala... |
| CVE-2022-32643 | MEDIUM | 6.4 | 0.2% | Feb 6, 2023 | In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit... |
| CVE-2022-32642 | MEDIUM | 6.4 | 0.1% | Feb 6, 2023 | In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
| CVE-2022-32595 | MEDIUM | 4.4 | 0.1% | Feb 6, 2023 | In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati... |
| CVE-2022-4902 | MEDIUM | 6.1 | 0.6% | Feb 6, 2023 | A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the... |
| CVE-2022-41342 | HIGH | 7.8 | 0.2% | Feb 6, 2023 | Improper buffer restrictions in the Intel(R) C++ Compiler Classic before version 2021.7.1 for some Intel(R) oneAPI Toolk... |
| CVE-2022-40196 | HIGH | 7.8 | 0.2% | Feb 6, 2023 | Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 and Intel C++ Compiler Classic... |
| CVE-2022-38136 | HIGH | 7.3 | 0.2% | Feb 6, 2023 | Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows be... |
| CVE-2022-2933 | MEDIUM | 5.4 | 0.5% | Feb 6, 2023 | The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2... |
| CVE-2022-47071 | CRITICAL | 9.8 | 25.9% | Feb 6, 2023 | In NVS365 V01, the background network test function can trigger command execution. |
| CVE-2022-48078 | CRITICAL | 9.8 | 0.9% | Feb 6, 2023 | pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTre... |
| CVE-2022-48019 | HIGH | 7.8 | 0.3% | Feb 6, 2023 | The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to per... |
| CVE-2022-48164 | HIGH | 7.5 | 3.1% | Feb 6, 2023 | An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthen... |
| CVE-2022-48085 | MEDIUM | 5.4 | 0.6% | Feb 6, 2023 | Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. |
| CVE-2022-44343 | HIGH | 7.5 | 0.6% | Feb 6, 2023 | CRMEB 4.4.4 is vulnerable to Any File download. |
| CVE-2022-45722 | MEDIUM | 6.1 | 0.4% | Feb 6, 2023 | ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-29416 | MEDIUM | 6.1 | 0.4% | Feb 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now