2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-32278HIGH8.8XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-control...
CVE-2022-29257HIGH7.2Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab...
CVE-2022-32564HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cook...
CVE-2022-32560HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
CVE-2022-32558HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during ...
CVE-2022-31054HIGH7.5Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRout...
CVE-2022-29798HIGH7.5There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause d...
CVE-2022-33174HIGH7.5Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas...
CVE-2022-23169HIGH7.2attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
CVE-2022-31761HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality...
CVE-2022-31757HIGH7.5The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect...
CVE-2022-31754HIGH7.5Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the av...
CVE-2022-31753HIGH7.5The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of th...
CVE-2022-31055HIGH7.5kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf clus...
CVE-2022-31762HIGH7.8The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privileg...
CVE-2022-29244HIGH7.5npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a worksp...
CVE-2022-24077HIGH7.8Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
CVE-2022-1969HIGH8.8The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ...
CVE-2022-1768HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param...
CVE-2022-1749HIGH8.8The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting...
CVE-2022-1659HIGH7.3Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which ca...
CVE-2022-1657HIGH8.8Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscribe...
CVE-2022-1654HIGH8.8Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu...
CVE-2022-1918HIGH8.8The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2022-1900HIGH8.8The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. Thi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now