2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32278 | HIGH | 8.8 | 1.5% | Jun 13, 2022 | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-control... |
| CVE-2022-29257 | HIGH | 7.2 | 0.8% | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab... |
| CVE-2022-32564 | HIGH | 7.5 | 1.1% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cook... |
| CVE-2022-32560 | HIGH | 7.5 | 0.9% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. |
| CVE-2022-32558 | HIGH | 7.5 | 1.1% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during ... |
| CVE-2022-31054 | HIGH | 7.5 | 1.5% | Jun 13, 2022 | Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRout... |
| CVE-2022-29798 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause d... |
| CVE-2022-33174 | HIGH | 7.5 | 13.4% | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas... |
| CVE-2022-23169 | HIGH | 7.2 | 0.4% | Jun 13, 2022 | attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. |
| CVE-2022-31761 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality... |
| CVE-2022-31757 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect... |
| CVE-2022-31754 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the av... |
| CVE-2022-31753 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of th... |
| CVE-2022-31055 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf clus... |
| CVE-2022-31762 | HIGH | 7.8 | 0.2% | Jun 13, 2022 | The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privileg... |
| CVE-2022-29244 | HIGH | 7.5 | 3.4% | Jun 13, 2022 | npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a worksp... |
| CVE-2022-24077 | HIGH | 7.8 | 0.3% | Jun 13, 2022 | Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection. |
| CVE-2022-1969 | HIGH | 8.8 | 0.8% | Jun 13, 2022 | The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ... |
| CVE-2022-1768 | HIGH | 7.5 | 12.0% | Jun 13, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param... |
| CVE-2022-1749 | HIGH | 8.8 | 0.8% | Jun 13, 2022 | The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting... |
| CVE-2022-1659 | HIGH | 7.3 | 0.8% | Jun 13, 2022 | Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which ca... |
| CVE-2022-1657 | HIGH | 8.8 | 1.6% | Jun 13, 2022 | Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscribe... |
| CVE-2022-1654 | HIGH | 8.8 | 1.5% | Jun 13, 2022 | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu... |
| CVE-2022-1918 | HIGH | 8.8 | 0.8% | Jun 13, 2022 | The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2022-1900 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. Thi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now