2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2137 | MEDIUM | 4.9 | 0.7% | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an ... |
| CVE-2022-2136 | MEDIUM | 6.5 | 9.0% | Jul 22, 2022 | The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow... |
| CVE-2022-1655 | MEDIUM | 6.5 | 0.5% | Jul 22, 2022 | An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session... |
| CVE-2022-36131 | MEDIUM | 6.1 | 0.5% | Jul 22, 2022 | The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Tem... |
| CVE-2022-2495 | MEDIUM | 4.8 | 0.5% | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. |
| CVE-2022-2494 | MEDIUM | 5.4 | 0.5% | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0. |
| CVE-2022-20916 | MEDIUM | 6.1 | 0.5% | Jul 22, 2022 | A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote... |
| CVE-2022-20913 | MEDIUM | 6.5 | 0.9% | Jul 22, 2022 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af... |
| CVE-2022-20909 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20908 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20907 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20906 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-34487 | MEDIUM | 5.3 | 2.6% | Jul 21, 2022 | Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress. |
| CVE-2022-33198 | MEDIUM | 5.3 | 2.6% | Jul 21, 2022 | Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress. |
| CVE-2022-31475 | MEDIUM | 4.9 | 0.7% | Jul 21, 2022 | Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.... |
| CVE-2022-30536 | MEDIUM | 4.8 | 0.6% | Jul 21, 2022 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at ... |
| CVE-2022-30337 | MEDIUM | 4.3 | 0.3% | Jul 21, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacke... |
| CVE-2022-28666 | MEDIUM | 5.3 | 1.2% | Jul 21, 2022 | Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leadi... |
| CVE-2022-36313 | MEDIUM | 5.5 | 0.4% | Jul 21, 2022 | An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file ... |
| CVE-2022-32289 | MEDIUM | 4.3 | 0.3% | Jul 21, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup s... |
| CVE-2022-30628 | MEDIUM | 5.5 | 0.2% | Jul 21, 2022 | It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/se... |
| CVE-2022-28877 | MEDIUM | 6.7 | 0.3% | Jul 21, 2022 | This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can ... |
| CVE-2022-28861 | MEDIUM | 5.9 | 0.4% | Jul 21, 2022 | The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Ax... |
| CVE-2022-28860 | MEDIUM | 5.9 | 0.7% | Jul 21, 2022 | An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the... |
| CVE-2022-31151 | MEDIUM | 6.5 | 0.6% | Jul 21, 2022 | Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now