2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42348MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-42346MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-42345MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-41418HIGH7.2An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows at...
CVE-2022-40607MEDIUM6.8 IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim ...
CVE-2022-3775HIGH7.1When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and he...
CVE-2022-35695MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-35693MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-30679MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-43289HIGH7.8Deark v.1.6.2 was discovered to contain a stack overflow via the do_prism_read_palette() function at /modules/atari-img....
CVE-2022-40435MEDIUM4.8Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerabil...
CVE-2022-47512MEDIUM5.5Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo...
CVE-2022-42947HIGH7.8A maliciously crafted X_B file when parsed through Autodesk Maya 2023 and 2022 can be used to write beyond the allocated...
CVE-2022-42946HIGH7.1Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. Th...
CVE-2022-42945HIGH7.8DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attac...
CVE-2022-31683MEDIUM5.4Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can s...
CVE-2022-28173CRITICAL9.8The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obta...
CVE-2022-4613MEDIUM6.5A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr...
CVE-2022-4612MEDIUM6.5A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified ...
CVE-2022-4611MEDIUM5.3A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser...
CVE-2022-4610MEDIUM5.5A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br...
CVE-2022-4125MEDIUM4.3The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popup...
CVE-2022-4124MEDIUM4.3The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which...
CVE-2022-4112MEDIUM4.8The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-4108MEDIUM4.9The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now