2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32218 | MEDIUM | 4.3 | 0.7% | Sep 23, 2022 | An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler meth... |
| CVE-2022-32217 | MEDIUM | 5.3 | 0.5% | Sep 23, 2022 | A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext ... |
| CVE-2022-30124 | MEDIUM | 6.8 | 0.6% | Sep 23, 2022 | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with ph... |
| CVE-2022-28886 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.so/aerdl.dll may go... |
| CVE-2022-26707 | MEDIUM | 5.5 | 0.3% | Sep 23, 2022 | An issue in the handling of environment variables was addressed with improved validation. This issue is fixed in macOS M... |
| CVE-2022-40748 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-40359 | MEDIUM | 6.1 | 1.3% | Sep 23, 2022 | Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php. |
| CVE-2022-40358 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafte... |
| CVE-2022-35721 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to e... |
| CVE-2022-35099 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/S... |
| CVE-2022-35098 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(Gfx... |
| CVE-2022-35097 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrue... |
| CVE-2022-35096 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. |
| CVE-2022-35095 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutpu... |
| CVE-2022-35094 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /... |
| CVE-2022-35093 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/St... |
| CVE-2022-35092 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c. |
| CVE-2022-35091 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf... |
| CVE-2022-22423 | MEDIUM | 5.5 | 0.2% | Sep 23, 2022 | IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause ... |
| CVE-2022-40215 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress. |
| CVE-2022-36417 | MEDIUM | 6.1 | 0.2% | Sep 23, 2022 | Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <=... |
| CVE-2022-40672 | MEDIUM | 4.8 | 0.4% | Sep 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CPO Shortcodes plugin <= 1.5.0 at WordPress. |
| CVE-2022-40671 | MEDIUM | 4.3 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Rate my Post – WP Rating System plugin <= 3.3.4 at WordPress. |
| CVE-2022-40195 | MEDIUM | 4.8 | 0.4% | Sep 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PCA Predict plugin <= 1.0.3 at WordPress. |
| CVE-2022-40193 | MEDIUM | 6.1 | 0.5% | Sep 23, 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordP... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now