2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23689 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23688 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23687 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23686 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23678 | MEDIUM | 5.9 | 0.8% | Sep 6, 2022 | A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communic... |
| CVE-2022-1628 | MEDIUM | 5.4 | 0.5% | Sep 6, 2022 | The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and ... |
| CVE-2022-26114 | MEDIUM | 6.1 | 0.4% | Sep 6, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before... |
| CVE-2022-34882 | MEDIUM | 6.5 | 0.7% | Sep 6, 2022 | Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r... |
| CVE-2022-38367 | MEDIUM | 5.3 | 0.4% | Sep 5, 2022 | The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an ... |
| CVE-2022-3127 | MEDIUM | 5.4 | 0.5% | Sep 5, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. |
| CVE-2022-2775 | MEDIUM | 5.5 | 0.6% | Sep 5, 2022 | The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow... |
| CVE-2022-2657 | MEDIUM | 4.3 | 0.3% | Sep 5, 2022 | The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in... |
| CVE-2022-2597 | MEDIUM | 5.4 | 0.4% | Sep 5, 2022 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks... |
| CVE-2022-2543 | MEDIUM | 6.1 | 0.5% | Sep 5, 2022 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks... |
| CVE-2022-2376 | MEDIUM | 5.3 | 1.4% | Sep 5, 2022 | The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to bo... |
| CVE-2022-2271 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privileg... |
| CVE-2022-3123 | MEDIUM | 6.1 | 0.9% | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. |
| CVE-2022-38752 | MEDIUM | 6.5 | 2.0% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38751 | MEDIUM | 6.5 | 1.5% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38750 | MEDIUM | 5.5 | 1.0% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38749 | MEDIUM | 6.5 | 1.6% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-39842 | MEDIUM | 6.1 | 0.6% | Sep 5, 2022 | An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the co... |
| CVE-2022-39050 | MEDIUM | 4.8 | 0.5% | Sep 5, 2022 | An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be ru... |
| CVE-2022-39049 | MEDIUM | 4.8 | 0.5% | Sep 5, 2022 | An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the cont... |
| CVE-2022-39840 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM). |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now