2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-32572HIGH8.8An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master ...
CVE-2022-32282HIGH8.8An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An atta...
CVE-2022-30605HIGH8.8A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f...
CVE-2022-30534HIGH8.8An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev ma...
CVE-2022-29468HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially...
CVE-2022-26061HIGH7.8A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-...
CVE-2022-25972HIGH7.8An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafte...
CVE-2022-25942HIGH7.8An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted...
CVE-2022-1930HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an at...
CVE-2022-37133HIGH7.5D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is re...
CVE-2022-36346HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
CVE-2022-34776HIGH7.5Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as h...
CVE-2022-34775HIGH7.5Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containi...
CVE-2022-34772HIGH8.8Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit...
CVE-2022-34770HIGH7.5Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive infor...
CVE-2022-34347HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-33900HIGH7.2PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
CVE-2022-2594HIGH8.8The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 all...
CVE-2022-2593HIGH7.2The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before insertin...
CVE-2022-2557HIGH8.8The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary f...
CVE-2022-2551HIGH7.5The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the...
CVE-2022-2544HIGH7.5The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, makin...
CVE-2022-2362HIGH7.5The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PH...
CVE-2022-25812HIGH7.2The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allo...
CVE-2022-25811HIGH7.2The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now