2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4577MEDIUM5.4The Easy Testimonials WordPress plugin before 3.9.3 does not validate and escape some of its shortcode attributes before...
CVE-2022-4489HIGH7.2The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privil...
CVE-2022-4459MEDIUM5.4The WP Show Posts WordPress plugin before 1.1.4 does not validate and escape some of its shortcode attributes before out...
CVE-2022-4384MEDIUM6.5The Stream WordPress plugin before 3.9.2 does not prevent users with little privileges on the site (like subscribers) fr...
CVE-2022-4321MEDIUM6.1The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Refl...
CVE-2022-32663HIGH7.5In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of s...
CVE-2022-32656MEDIUM6.7In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala...
CVE-2022-32655MEDIUM6.7In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala...
CVE-2022-32654MEDIUM6.7In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escala...
CVE-2022-32643MEDIUM6.4In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit...
CVE-2022-32642MEDIUM6.4In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ...
CVE-2022-32595MEDIUM4.4In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati...
CVE-2022-4902MEDIUM6.1A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the...
CVE-2022-41342HIGH7.8Improper buffer restrictions in the Intel(R) C++ Compiler Classic before version 2021.7.1 for some Intel(R) oneAPI Toolk...
CVE-2022-40196HIGH7.8Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 and Intel C++ Compiler Classic...
CVE-2022-38136HIGH7.3Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows be...
CVE-2022-2933MEDIUM5.4The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2...
CVE-2022-47071CRITICAL9.8In NVS365 V01, the background network test function can trigger command execution.
CVE-2022-48078CRITICAL9.8pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTre...
CVE-2022-48019HIGH7.8The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to per...
CVE-2022-48164HIGH7.5An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthen...
CVE-2022-48085MEDIUM5.4Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
CVE-2022-44343HIGH7.5CRMEB 4.4.4 is vulnerable to Any File download.
CVE-2022-45722MEDIUM6.1ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-29416MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now