2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3257 | MEDIUM | 6.5 | 1.1% | Sep 23, 2022 | Mattermost version 7.1.x and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded w... |
| CVE-2022-38460 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NOTICE BOARD plugin <= 1.1 at WordPress. |
| CVE-2022-38061 | MEDIUM | 5.7 | 0.6% | Sep 23, 2022 | Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at WordPress. |
| CVE-2022-37342 | MEDIUM | 4.8 | 0.5% | Sep 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability Add Shortcodes Actions And Filters plugin <= 2.0.... |
| CVE-2022-37328 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in Themes Awesome History Timeline plugin <= 1.0... |
| CVE-2022-36791 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Awesome UG Torro Forms plugin <= 1.0.16 ... |
| CVE-2022-35238 | MEDIUM | 5.3 | 0.5% | Sep 23, 2022 | Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. |
| CVE-2022-40213 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin ... |
| CVE-2022-3144 | MEDIUM | 4.8 | 0.6% | Sep 23, 2022 | The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve... |
| CVE-2022-38703 | MEDIUM | 4.8 | 0.4% | Sep 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <=... |
| CVE-2022-38095 | MEDIUM | 4.3 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at... |
| CVE-2022-37339 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 a... |
| CVE-2022-37338 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <... |
| CVE-2022-37330 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPr... |
| CVE-2022-30121 | MEDIUM | 6.7 | 0.3% | Sep 23, 2022 | The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only fo... |
| CVE-2022-2937 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Descr... |
| CVE-2022-40716 | MEDIUM | 6.5 | 0.8% | Sep 23, 2022 | HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CS... |
| CVE-2022-40979 | MEDIUM | 5.3 | 0.3% | Sep 23, 2022 | In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perf... |
| CVE-2022-2785 | MEDIUM | 5.5 | 0.2% | Sep 23, 2022 | There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passe... |
| CVE-2022-33683 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, eve... |
| CVE-2022-33682 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, t... |
| CVE-2022-33681 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in... |
| CVE-2022-24280 | MEDIUM | 6.5 | 1.2% | Sep 23, 2022 | Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection... |
| CVE-2022-39239 | MEDIUM | 5.4 | 0.3% | Sep 23, 2022 | netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass... |
| CVE-2022-39230 | MEDIUM | 6.5 | 0.6% | Sep 23, 2022 | fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Version... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now