2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4060 | CRITICAL | 9.8 | 42.7% | Jan 16, 2023 | The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, makin... |
| CVE-2022-47630 | HIGH | 7.4 | 0.6% | Jan 16, 2023 | Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects... |
| CVE-2022-3904 | MEDIUM | 6.1 | 1.3% | Jan 16, 2023 | The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section... |
| CVE-2022-2658 | MEDIUM | 4.8 | 0.5% | Jan 16, 2023 | The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users su... |
| CVE-2022-4890 | CRITICAL | 9.8 | 0.8% | Jan 16, 2023 | A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some un... |
| CVE-2022-45438 | MEDIUM | 5.3 | 1.2% | Jan 16, 2023 | When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat... |
| CVE-2022-43721 | MEDIUM | 5.4 | 1.0% | Jan 16, 2023 | An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could ... |
| CVE-2022-43720 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not ... |
| CVE-2022-43719 | HIGH | 8.8 | 0.6% | Jan 16, 2023 | Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue a... |
| CVE-2022-43718 | MEDIUM | 5.4 | 1.3% | Jan 16, 2023 | Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by aut... |
| CVE-2022-43717 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vec... |
| CVE-2022-41703 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a speci... |
| CVE-2022-4258 | HIGH | 7.8 | 0.2% | Jan 16, 2023 | In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to ... |
| CVE-2022-4889 | CRITICAL | 9.8 | 0.6% | Jan 15, 2023 | A vulnerability classified as critical was found in visegripped Stracker. Affected by this vulnerability is the function... |
| CVE-2022-2815 | MEDIUM | 6.5 | 0.6% | Jan 14, 2023 | Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. |
| CVE-2022-1812 | CRITICAL | 9.8 | 30.8% | Jan 14, 2023 | Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10. |
| CVE-2022-45353 | HIGH | 8.1 | 0.5% | Jan 14, 2023 | Broken Access Control in Betheme theme <= 26.6.1 on WordPress. |
| CVE-2022-38467 | MEDIUM | 6.1 | 0.8% | Jan 14, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver. |
| CVE-2022-38287 | — | — | — | Jan 14, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-41956 | MEDIUM | 6.5 | 1.8% | Jan 14, 2023 | Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en... |
| CVE-2022-41955 | HIGH | 8.8 | 1.5% | Jan 14, 2023 | Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en... |
| CVE-2022-23532 | MEDIUM | 6.5 | 0.7% | Jan 14, 2023 | APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A... |
| CVE-2022-41721 | HIGH | 7.5 | 1.8% | Jan 13, 2023 | A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP reque... |
| CVE-2022-46093 | HIGH | 8.2 | 0.7% | Jan 13, 2023 | Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the ... |
| CVE-2022-45299 | CRITICAL | 9.8 | 1.3% | Jan 13, 2023 | An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now