2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-36379HIGH8.8Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 a...
CVE-2022-36292HIGH8.8Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress.
CVE-2022-36288HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-36285HIGH7.2Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at...
CVE-2022-28883HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack functi...
CVE-2022-28882HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go i...
CVE-2022-35203HIGH7.2An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system informat...
CVE-2022-34486HIGH7.2Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administ...
CVE-2022-25888HIGH7.5The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of rece...
CVE-2022-25761HIGH7.5The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) du...
CVE-2022-25304HIGH7.5All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missin...
CVE-2022-25302HIGH7.5All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed c...
CVE-2022-25231HIGH7.5The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA ...
CVE-2022-24381HIGH7.5All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the nu...
CVE-2022-24298HIGH7.5All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for...
CVE-2022-21208HIGH7.5The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number...
CVE-2022-33916HIGH7.5OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive inf...
CVE-2022-38668HIGH7.5HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack m...
CVE-2022-38171HIGH7.8Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2S...
CVE-2022-34652HIGH8.8A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ...
CVE-2022-33149HIGH8.8A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ...
CVE-2022-33148HIGH8.8A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ...
CVE-2022-33147HIGH8.8A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ...
CVE-2022-32778HIGH7.5An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7...
CVE-2022-32777HIGH7.5An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now