2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-48621HIGH7.5Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulne...
CVE-2022-41738HIGH7.5IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connectio...
CVE-2022-23092HIGH8.8The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message co...
CVE-2022-23090HIGH7.7The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error ca...
CVE-2022-23087HIGH8.8The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These ...
CVE-2022-23086HIGH7.8Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified si...
CVE-2022-23085HIGH8.2A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bo...
CVE-2022-23084HIGH7.5The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This...
CVE-2022-34309HIGH7.5IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2022-34310HIGH7.5IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2022-48622HIGH7.8In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory co...
CVE-2022-45792HIGH7.8Project files may contain malicious contents which the software will use to create files on the filesystem. This allows ...
CVE-2022-45845HIGH8.8Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a th...
CVE-2022-45083HIGH7.2Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User ...
CVE-2022-42884HIGH8.8Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a th...
CVE-2022-41790HIGH8.8Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Fo...
CVE-2022-41990HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Ta...
CVE-2022-40203HIGH8.8Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dy...
CVE-2022-3899HIGH8.1The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File M...
CVE-2022-3764HIGH7.2The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
CVE-2022-3604HIGH7.8The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could...
CVE-2022-1538HIGH7.2Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such ...
CVE-2022-45794HIGH7.5An attacker with network access to the affected PLC (CJ-series and CS-series PLCs, all versions) may use a network proto...
CVE-2022-47965HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to ex...
CVE-2022-47915HIGH7.8The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13. An app may be able to ex...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now