2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42348 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-42346 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-42345 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-41418 | HIGH | 7.2 | 1.2% | Dec 19, 2022 | An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows at... |
| CVE-2022-40607 | MEDIUM | 6.8 | 0.9% | Dec 19, 2022 | IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim ... |
| CVE-2022-3775 | HIGH | 7.1 | 0.9% | Dec 19, 2022 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and he... |
| CVE-2022-35695 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-35693 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-30679 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-43289 | HIGH | 7.8 | 0.4% | Dec 19, 2022 | Deark v.1.6.2 was discovered to contain a stack overflow via the do_prism_read_palette() function at /modules/atari-img.... |
| CVE-2022-40435 | MEDIUM | 4.8 | 0.6% | Dec 19, 2022 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerabil... |
| CVE-2022-47512 | MEDIUM | 5.5 | 0.2% | Dec 19, 2022 | Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo... |
| CVE-2022-42947 | HIGH | 7.8 | 0.3% | Dec 19, 2022 | A maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated... |
| CVE-2022-42946 | HIGH | 7.1 | 0.3% | Dec 19, 2022 | Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. Th... |
| CVE-2022-42945 | HIGH | 7.8 | 0.3% | Dec 19, 2022 | DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attac... |
| CVE-2022-31683 | MEDIUM | 5.4 | 0.4% | Dec 19, 2022 | Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can s... |
| CVE-2022-28173 | CRITICAL | 9.8 | 0.6% | Dec 19, 2022 | The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obta... |
| CVE-2022-4613 | MEDIUM | 6.5 | 0.7% | Dec 19, 2022 | A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr... |
| CVE-2022-4612 | MEDIUM | 6.5 | 0.9% | Dec 19, 2022 | A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified ... |
| CVE-2022-4611 | MEDIUM | 5.3 | 1.2% | Dec 19, 2022 | A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser... |
| CVE-2022-4610 | MEDIUM | 5.5 | 0.2% | Dec 19, 2022 | A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br... |
| CVE-2022-4125 | MEDIUM | 4.3 | 0.3% | Dec 19, 2022 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popup... |
| CVE-2022-4124 | MEDIUM | 4.3 | 0.3% | Dec 19, 2022 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which... |
| CVE-2022-4112 | MEDIUM | 4.8 | 0.5% | Dec 19, 2022 | The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2022-4108 | MEDIUM | 4.9 | 0.8% | Dec 19, 2022 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now