2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38975 | MEDIUM | 5.4 | 0.5% | Sep 27, 2022 | DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to in... |
| CVE-2022-38335 | MEDIUM | 5.4 | 0.7% | Sep 27, 2022 | Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template mo... |
| CVE-2022-37028 | MEDIUM | 5.4 | 0.4% | Sep 27, 2022 | ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker ... |
| CVE-2022-23006 | MEDIUM | 6.7 | 0.3% | Sep 27, 2022 | A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i... |
| CVE-2022-30003 | MEDIUM | 5.4 | 0.5% | Sep 26, 2022 | Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register ... |
| CVE-2022-40044 | MEDIUM | 5.4 | 0.6% | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Nam... |
| CVE-2022-3201 | MEDIUM | 5.4 | 0.6% | Sep 26, 2022 | Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an ... |
| CVE-2022-3057 | MEDIUM | 6.5 | 0.5% | Sep 26, 2022 | Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak... |
| CVE-2022-3056 | MEDIUM | 6.5 | 0.9% | Sep 26, 2022 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote atta... |
| CVE-2022-3054 | MEDIUM | 6.5 | 0.6% | Sep 26, 2022 | Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potenti... |
| CVE-2022-3053 | MEDIUM | 4.3 | 0.5% | Sep 26, 2022 | Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to... |
| CVE-2022-3048 | MEDIUM | 6.8 | 0.4% | Sep 26, 2022 | Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a loca... |
| CVE-2022-3047 | MEDIUM | 6.5 | 0.4% | Sep 26, 2022 | Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convin... |
| CVE-2022-3044 | MEDIUM | 6.5 | 0.8% | Sep 26, 2022 | Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had... |
| CVE-2022-2861 | MEDIUM | 6.5 | 0.6% | Sep 26, 2022 | Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convince... |
| CVE-2022-2860 | MEDIUM | 6.5 | 0.8% | Sep 26, 2022 | Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass ... |
| CVE-2022-2856 | MEDIUM | 6.5 | 4.5% | Sep 26, 2022 | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remo... |
| CVE-2022-39219 | MEDIUM | 6.5 | 0.9% | Sep 26, 2022 | Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.... |
| CVE-2022-3299 | MEDIUM | 6.5 | 0.9% | Sep 26, 2022 | A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability i... |
| CVE-2022-3135 | MEDIUM | 4.8 | 0.5% | Sep 26, 2022 | The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2022-3098 | MEDIUM | 4.3 | 0.3% | Sep 26, 2022 | The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-3074 | MEDIUM | 4.8 | 0.5% | Sep 26, 2022 | The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users t... |
| CVE-2022-3070 | MEDIUM | 4.8 | 0.5% | Sep 26, 2022 | The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users su... |
| CVE-2022-3069 | MEDIUM | 4.8 | 0.5% | Sep 26, 2022 | The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users suc... |
| CVE-2022-3062 | MEDIUM | 6.1 | 37.4% | Sep 26, 2022 | The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now