2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3860 | HIGH | 8.8 | 0.9% | Jan 2, 2023 | The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a paramete... |
| CVE-2022-3241 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using t... |
| CVE-2022-48197 | MEDIUM | 6.1 | 6.6% | Jan 2, 2023 | Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree... |
| CVE-2022-42475 | CRITICAL | 9.8 | 99.5% | Jan 2, 2023 | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 ... |
| CVE-2022-47634 | HIGH | 8.1 | 0.5% | Jan 1, 2023 | M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access an... |
| CVE-2022-45213 | MEDIUM | 5.3 | 0.6% | Jan 1, 2023 | perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL. |
| CVE-2022-45027 | MEDIUM | 5.3 | 0.6% | Jan 1, 2023 | perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determin... |
| CVE-2022-40711 | MEDIUM | 4.8 | 0.5% | Jan 1, 2023 | PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can ... |
| CVE-2022-37787 | MEDIUM | 6.1 | 0.5% | Jan 1, 2023 | An issue was discovered in WeCube platform 3.2.2. A DOM XSS vulnerability has been found on the plugin database executio... |
| CVE-2022-37786 | MEDIUM | 6.3 | 0.5% | Jan 1, 2023 | An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources... |
| CVE-2022-37785 | HIGH | 7.5 | 0.5% | Jan 1, 2023 | An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal pl... |
| CVE-2022-34324 | HIGH | 8.8 | 11.8% | Jan 1, 2023 | Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data ... |
| CVE-2022-34323 | MEDIUM | 5.4 | 0.4% | Jan 1, 2023 | Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript ... |
| CVE-2022-34322 | CRITICAL | 9 | 0.8% | Jan 1, 2023 | Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScri... |
| CVE-2022-48198 | CRITICAL | 9.8 | 1.1% | Jan 1, 2023 | The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who contr... |
| CVE-2022-47952 | LOW | 3.3 | 0.7% | Jan 1, 2023 | lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, ... |
| CVE-2022-43830 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43829 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43828 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43827 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43826 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43825 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43824 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43823 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
| CVE-2022-43822 | — | — | — | Jan 1, 2023 | Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now