2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32834 | MEDIUM | 5.5 | 0.5% | Aug 24, 2022 | An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Su... |
| CVE-2022-34837 | MEDIUM | 6.1 | 0.1% | Aug 24, 2022 | Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit th... |
| CVE-2022-2569 | MEDIUM | 5.5 | 0.1% | Aug 24, 2022 | The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session d... |
| CVE-2022-37153 | MEDIUM | 6.1 | 1.4% | Aug 24, 2022 | An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.logi... |
| CVE-2022-33172 | MEDIUM | 5.5 | 0.2% | Aug 24, 2022 | de.fac2 1.34 allows bypassing the User Presence protection mechanism when there is malware on the victim's PC. |
| CVE-2022-38089 | MEDIUM | 5.4 | 0.8% | Aug 24, 2022 | Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-ad... |
| CVE-2022-38080 | MEDIUM | 5.4 | 0.8% | Aug 24, 2022 | Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel... |
| CVE-2022-37418 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote at... |
| CVE-2022-37305 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform ... |
| CVE-2022-36945 | MEDIUM | 6.4 | 0.9% | Aug 24, 2022 | The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform ... |
| CVE-2022-38463 | MEDIUM | 6.1 | 2.3% | Aug 23, 2022 | ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality. |
| CVE-2022-38172 | MEDIUM | 6.1 | 0.5% | Aug 23, 2022 | ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performanc... |
| CVE-2022-38665 | MEDIUM | 6.5 | 0.7% | Aug 23, 2022 | Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration fi... |
| CVE-2022-38664 | MEDIUM | 5.4 | 0.6% | Aug 23, 2022 | Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Confi... |
| CVE-2022-38663 | MEDIUM | 6.5 | 0.8% | Aug 23, 2022 | Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log... |
| CVE-2022-37428 | MEDIUM | 6.5 | 1.2% | Aug 23, 2022 | PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upo... |
| CVE-2022-36405 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 ... |
| CVE-2022-36347 | MEDIUM | 5.4 | 0.5% | Aug 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest pl... |
| CVE-2022-36341 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash s... |
| CVE-2022-36282 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2... |
| CVE-2022-35242 | MEDIUM | 5.3 | 0.5% | Aug 23, 2022 | Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at... |
| CVE-2022-35235 | MEDIUM | 4.9 | 0.9% | Aug 23, 2022 | Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. |
| CVE-2022-34868 | MEDIUM | 6.5 | 0.9% | Aug 23, 2022 | Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress. |
| CVE-2022-34658 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager ... |
| CVE-2022-34648 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO fi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now