2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4651 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which ... |
| CVE-2022-4649 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which... |
| CVE-2022-4553 | MEDIUM | 4.3 | 0.3% | Jan 30, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow a... |
| CVE-2022-4552 | MEDIUM | 6.1 | 0.3% | Jan 30, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing saniti... |
| CVE-2022-4496 | MEDIUM | 6.1 | 0.6% | Jan 30, 2023 | The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 be... |
| CVE-2022-4472 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4470 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes... |
| CVE-2022-4395 | CRITICAL | 9.8 | 17.6% | Jan 30, 2023 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthe... |
| CVE-2022-4306 | MEDIUM | 5.4 | 0.8% | Jan 30, 2023 | The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting ... |
| CVE-2022-26872 | HIGH | 8.8 | 0.8% | Jan 30, 2023 | AMI Megarac Password reset interception via API |
| CVE-2022-23334 | CRITICAL | 9.8 | 0.5% | Jan 30, 2023 | The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries... |
| CVE-2022-46087 | MEDIUM | 5.4 | 0.6% | Jan 30, 2023 | CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin use... |
| CVE-2022-45788 | CRITICAL | 9.8 | 1.2% | Jan 30, 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code exe... |
| CVE-2022-42484 | CRITICAL | 9.8 | 6.0% | Jan 30, 2023 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially... |
| CVE-2022-38451 | HIGH | 7.5 | 2.1% | Jan 30, 2023 | A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially craf... |
| CVE-2022-2988 | HIGH | 7.5 | 0.4% | Jan 30, 2023 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a mali... |
| CVE-2022-46359 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46358 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46357 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-46356 | HIGH | 8.8 | 0.2% | Jan 30, 2023 | Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary... |
| CVE-2022-25967 | HIGH | 8.8 | 2.0% | Jan 30, 2023 | Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine co... |
| CVE-2022-25936 | HIGH | 7.5 | 1.3% | Jan 30, 2023 | Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the fi... |
| CVE-2022-48303 | MEDIUM | 5.5 | 4.5% | Jan 30, 2023 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum... |
| CVE-2022-27596 | CRITICAL | 9.8 | 2.7% | Jan 30, 2023 | A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows ... |
| CVE-2022-48285 | HIGH | 7.3 | 1.4% | Jan 29, 2023 | loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now