2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38067 | MEDIUM | 5.3 | 0.5% | Sep 9, 2022 | Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. |
| CVE-2022-38064 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission cont... |
| CVE-2022-38058 | MEDIUM | 4.3 | 0.5% | Sep 9, 2022 | Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress. |
| CVE-2022-37412 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plu... |
| CVE-2022-37407 | MEDIUM | 5.4 | 0.5% | Sep 9, 2022 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 ... |
| CVE-2022-37404 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at W... |
| CVE-2022-37403 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1... |
| CVE-2022-37335 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0.... |
| CVE-2022-37299 | MEDIUM | 6.5 | 2.8% | Sep 9, 2022 | An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file re... |
| CVE-2022-36875 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 al... |
| CVE-2022-36874 | MEDIUM | 6.2 | 0.2% | Sep 9, 2022 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows... |
| CVE-2022-36873 | MEDIUM | 6.5 | 0.2% | Sep 9, 2022 | Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.220811... |
| CVE-2022-36872 | MEDIUM | 6.5 | 0.2% | Sep 9, 2022 | Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for ... |
| CVE-2022-36871 | MEDIUM | 6.5 | 0.2% | Sep 9, 2022 | Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for G... |
| CVE-2022-36870 | MEDIUM | 6.5 | 0.2% | Sep 9, 2022 | Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and... |
| CVE-2022-36869 | MEDIUM | 6.1 | 0.2% | Sep 9, 2022 | Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attac... |
| CVE-2022-36867 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive inf... |
| CVE-2022-36861 | MEDIUM | 5.3 | 0.1% | Sep 9, 2022 | Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected... |
| CVE-2022-36859 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigg... |
| CVE-2022-36854 | MEDIUM | 5.5 | 0.1% | Sep 9, 2022 | Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized inf... |
| CVE-2022-36851 | MEDIUM | 4.6 | 0.3% | Sep 9, 2022 | Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data ... |
| CVE-2022-36850 | MEDIUM | 4.7 | 0.1% | Sep 9, 2022 | Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary fi... |
| CVE-2022-36848 | MEDIUM | 5.5 | 0.1% | Sep 9, 2022 | Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to ca... |
| CVE-2022-36356 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object p... |
| CVE-2022-36280 | MEDIUM | 5.5 | 0.6% | Sep 9, 2022 | An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now