2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36379 | HIGH | 8.8 | 0.4% | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 a... |
| CVE-2022-36292 | HIGH | 8.8 | 0.3% | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. |
| CVE-2022-36288 | HIGH | 8.8 | 0.3% | Aug 23, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. |
| CVE-2022-36285 | HIGH | 7.2 | 0.9% | Aug 23, 2022 | Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at... |
| CVE-2022-28883 | HIGH | 7.5 | 0.5% | Aug 23, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack functi... |
| CVE-2022-28882 | HIGH | 7.5 | 0.4% | Aug 23, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go i... |
| CVE-2022-35203 | HIGH | 7.2 | 2.0% | Aug 23, 2022 | An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system informat... |
| CVE-2022-34486 | HIGH | 7.2 | 1.1% | Aug 23, 2022 | Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administ... |
| CVE-2022-25888 | HIGH | 7.5 | 1.0% | Aug 23, 2022 | The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of rece... |
| CVE-2022-25761 | HIGH | 7.5 | 1.1% | Aug 23, 2022 | The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) du... |
| CVE-2022-25304 | HIGH | 7.5 | 1.1% | Aug 23, 2022 | All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missin... |
| CVE-2022-25302 | HIGH | 7.5 | 0.7% | Aug 23, 2022 | All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed c... |
| CVE-2022-25231 | HIGH | 7.5 | 1.0% | Aug 23, 2022 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA ... |
| CVE-2022-24381 | HIGH | 7.5 | 0.7% | Aug 23, 2022 | All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the nu... |
| CVE-2022-24298 | HIGH | 7.5 | 0.8% | Aug 23, 2022 | All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for... |
| CVE-2022-21208 | HIGH | 7.5 | 1.2% | Aug 23, 2022 | The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number... |
| CVE-2022-33916 | HIGH | 7.5 | 1.0% | Aug 23, 2022 | OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive inf... |
| CVE-2022-38668 | HIGH | 7.5 | 1.1% | Aug 22, 2022 | HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack m... |
| CVE-2022-38171 | HIGH | 7.8 | 0.3% | Aug 22, 2022 | Xpdf prior to version 4.04 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIG2S... |
| CVE-2022-34652 | HIGH | 8.8 | 0.9% | Aug 22, 2022 | A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ... |
| CVE-2022-33149 | HIGH | 8.8 | 1.6% | Aug 22, 2022 | A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ... |
| CVE-2022-33148 | HIGH | 8.8 | 1.0% | Aug 22, 2022 | A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ... |
| CVE-2022-33147 | HIGH | 8.8 | 1.6% | Aug 22, 2022 | A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. ... |
| CVE-2022-32778 | HIGH | 7.5 | 2.0% | Aug 22, 2022 | An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7... |
| CVE-2022-32777 | HIGH | 7.5 | 2.0% | Aug 22, 2022 | An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now