2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35725 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at Wor... |
| CVE-2022-35275 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For ... |
| CVE-2022-2905 | MEDIUM | 5.5 | 0.3% | Sep 9, 2022 | An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call fu... |
| CVE-2022-26394 | MEDIUM | 5.4 | 0.3% | Sep 9, 2022 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker ... |
| CVE-2022-26392 | MEDIUM | 6.5 | 0.6% | Sep 9, 2022 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is ... |
| CVE-2022-26390 | MEDIUM | 4.2 | 0.4% | Sep 9, 2022 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pum... |
| CVE-2022-2528 | MEDIUM | 6.5 | 0.4% | Sep 9, 2022 | In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions... |
| CVE-2022-2925 | MEDIUM | 5.4 | 0.7% | Sep 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1. |
| CVE-2022-40307 | MEDIUM | 4.7 | 0.2% | Sep 9, 2022 | An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition w... |
| CVE-2022-36097 | MEDIUM | 6.1 | 57.4% | Sep 8, 2022 | XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki... |
| CVE-2022-36095 | MEDIUM | 4.3 | 0.3% | Sep 8, 2022 | XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Re... |
| CVE-2022-38256 | MEDIUM | 5.4 | 0.4% | Sep 8, 2022 | TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execu... |
| CVE-2022-27969 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET req... |
| CVE-2022-27968 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via ... |
| CVE-2022-27967 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a... |
| CVE-2022-3153 | MEDIUM | 5.5 | 0.5% | Sep 8, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404. |
| CVE-2022-36736 | MEDIUM | 6.1 | 0.6% | Sep 8, 2022 | Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking... |
| CVE-2022-20863 | MEDIUM | 5.3 | 0.8% | Sep 8, 2022 | A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, rem... |
| CVE-2022-3148 | MEDIUM | 6.1 | 0.5% | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. |
| CVE-2022-3138 | MEDIUM | 6.1 | 0.5% | Sep 8, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0. |
| CVE-2022-38400 | MEDIUM | 5.9 | 1.2% | Sep 8, 2022 | Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use... |
| CVE-2022-38399 | MEDIUM | 6.8 | 0.3% | Sep 8, 2022 | Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-... |
| CVE-2022-37146 | MEDIUM | 5.3 | 0.7% | Sep 8, 2022 | The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login a... |
| CVE-2022-36088 | MEDIUM | 5.5 | 0.2% | Sep 7, 2022 | GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to ... |
| CVE-2022-38254 | MEDIUM | 6.1 | 1.7% | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now