2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26117 | HIGH | 8.8 | 0.9% | Jul 18, 2022 | An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.... |
| CVE-2022-32387 | HIGH | 7.5 | 0.9% | Jul 18, 2022 | In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler. |
| CVE-2022-2444 | HIGH | 8.8 | 1.8% | Jul 18, 2022 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust... |
| CVE-2022-2443 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin... |
| CVE-2022-2435 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1... |
| CVE-2022-2039 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2022-2001 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2022-23745 | HIGH | 7.5 | 14.9% | Jul 18, 2022 | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could resul... |
| CVE-2022-1912 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2022-1565 | HIGH | 7.2 | 11.3% | Jul 18, 2022 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo... |
| CVE-2022-34902 | HIGH | 7.8 | 0.3% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39... |
| CVE-2022-34901 | HIGH | 7.8 | 0.3% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39... |
| CVE-2022-34900 | HIGH | 7.8 | 0.4% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39... |
| CVE-2022-34899 | HIGH | 7.8 | 0.2% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39... |
| CVE-2022-34892 | HIGH | 7.8 | 0.2% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel... |
| CVE-2022-34891 | HIGH | 7.8 | 0.3% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel... |
| CVE-2022-34890 | HIGH | 8.8 | 0.3% | Jul 18, 2022 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt... |
| CVE-2022-34889 | HIGH | 8.2 | 0.3% | Jul 18, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (... |
| CVE-2022-35404 | HIGH | 8.2 | 3.8% | Jul 18, 2022 | ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and... |
| CVE-2022-32450 | HIGH | 7.1 | 0.5% | Jul 18, 2022 | AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own ... |
| CVE-2022-30627 | HIGH | 7.5 | 0.3% | Jul 18, 2022 | This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104... |
| CVE-2022-30626 | HIGH | 7.5 | 0.2% | Jul 18, 2022 | Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, ... |
| CVE-2022-30624 | HIGH | 7.5 | 0.3% | Jul 18, 2022 | Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password. |
| CVE-2022-30620 | HIGH | 8.8 | 0.4% | Jul 18, 2022 | On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" priv... |
| CVE-2022-24691 | HIGH | 7.1 | 0.8% | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated user... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now