2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32572 | HIGH | 8.8 | 22.7% | Aug 22, 2022 | An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master ... |
| CVE-2022-32282 | HIGH | 8.8 | 1.6% | Aug 22, 2022 | An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An atta... |
| CVE-2022-30605 | HIGH | 8.8 | 4.1% | Aug 22, 2022 | A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f... |
| CVE-2022-30534 | HIGH | 8.8 | 74.5% | Aug 22, 2022 | An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev ma... |
| CVE-2022-29468 | HIGH | 8.8 | 1.4% | Aug 22, 2022 | A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially... |
| CVE-2022-26061 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-... |
| CVE-2022-25972 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafte... |
| CVE-2022-25942 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted... |
| CVE-2022-1930 | HIGH | 7.5 | 0.8% | Aug 22, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an at... |
| CVE-2022-37133 | HIGH | 7.5 | 1.1% | Aug 22, 2022 | D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is re... |
| CVE-2022-36346 | HIGH | 8.8 | 0.3% | Aug 22, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress. |
| CVE-2022-34776 | HIGH | 7.5 | 0.4% | Aug 22, 2022 | Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as h... |
| CVE-2022-34775 | HIGH | 7.5 | 0.4% | Aug 22, 2022 | Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containi... |
| CVE-2022-34772 | HIGH | 8.8 | 0.5% | Aug 22, 2022 | Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit... |
| CVE-2022-34770 | HIGH | 7.5 | 0.4% | Aug 22, 2022 | Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive infor... |
| CVE-2022-34347 | HIGH | 8.8 | 0.3% | Aug 22, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. |
| CVE-2022-33900 | HIGH | 7.2 | 0.7% | Aug 22, 2022 | PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress. |
| CVE-2022-2594 | HIGH | 8.8 | 1.3% | Aug 22, 2022 | The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 all... |
| CVE-2022-2593 | HIGH | 7.2 | 1.1% | Aug 22, 2022 | The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before insertin... |
| CVE-2022-2557 | HIGH | 8.8 | 1.3% | Aug 22, 2022 | The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary f... |
| CVE-2022-2551 | HIGH | 7.5 | 12.5% | Aug 22, 2022 | The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the... |
| CVE-2022-2544 | HIGH | 7.5 | 3.2% | Aug 22, 2022 | The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, makin... |
| CVE-2022-2362 | HIGH | 7.5 | 1.0% | Aug 22, 2022 | The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PH... |
| CVE-2022-25812 | HIGH | 7.2 | 1.4% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allo... |
| CVE-2022-25811 | HIGH | 7.2 | 1.2% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now