2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2330 | MEDIUM | 6.5 | 0.7% | Aug 30, 2022 | Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows... |
| CVE-2022-26529 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmente... |
| CVE-2022-26528 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the leng... |
| CVE-2022-26527 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size... |
| CVE-2022-25646 | MEDIUM | 6.1 | 0.7% | Aug 30, 2022 | All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of v... |
| CVE-2022-25635 | MEDIUM | 6.5 | 0.3% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcas... |
| CVE-2022-21385 | MEDIUM | 6.2 | 0.3% | Aug 29, 2022 | A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Bas... |
| CVE-2022-3035 | MEDIUM | 4.8 | 0.6% | Aug 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11. |
| CVE-2022-36037 | MEDIUM | 5.4 | 0.7% | Aug 29, 2022 | kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal int... |
| CVE-2022-2638 | MEDIUM | 6.5 | 0.9% | Aug 29, 2022 | The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which... |
| CVE-2022-2599 | MEDIUM | 6.1 | 1.0% | Aug 29, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some par... |
| CVE-2022-2538 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an ... |
| CVE-2022-2537 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters ... |
| CVE-2022-2374 | MEDIUM | 4.8 | 0.5% | Aug 29, 2022 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, whic... |
| CVE-2022-2373 | MEDIUM | 5.3 | 1.4% | Aug 29, 2022 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing u... |
| CVE-2022-2267 | MEDIUM | 4.3 | 0.6% | Aug 29, 2022 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as ... |
| CVE-2022-2080 | MEDIUM | 4.3 | 0.6% | Aug 29, 2022 | The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher ... |
| CVE-2022-2034 | MEDIUM | 5.3 | 1.8% | Aug 29, 2022 | The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing ... |
| CVE-2022-1663 | MEDIUM | 6.5 | 0.5% | Aug 29, 2022 | The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preve... |
| CVE-2022-36033 | MEDIUM | 6.1 | 1.2% | Aug 29, 2022 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup ma... |
| CVE-2022-27546 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-... |
| CVE-2022-35962 | MEDIUM | 5.7 | 0.9% | Aug 29, 2022 | Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version ... |
| CVE-2022-31677 | MEDIUM | 5.4 | 0.4% | Aug 29, 2022 | An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticati... |
| CVE-2022-2953 | MEDIUM | 5.5 | 0.5% | Aug 29, 2022 | LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a d... |
| CVE-2022-1204 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user conne... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now