2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3877MEDIUM5.4A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser...
CVE-2022-3876MEDIUM6.5A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br...
CVE-2022-3875HIGH7.5A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chro...
CVE-2022-38662MEDIUM6.1 In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
CVE-2022-38659HIGH7.8In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-d...
CVE-2022-38653MEDIUM5.4In HCL Digital Experience, customized XSS payload can be constructed such that it is served in the application unencoded...
CVE-2022-37392MEDIUM5.3Improper Check for Unusual or Exceptional Conditions vulnerability in handling the requests to Apache Traffic Server. T...
CVE-2022-32749HIGH7.5 Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an...
CVE-2022-4427CRITICAL9.8Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via Tic...
CVE-2022-47549MEDIUM6.4An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TE...
CVE-2022-47547MEDIUM5.3GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the net...
CVE-2022-46288MEDIUM6.1Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to...
CVE-2022-46287MEDIUM6.1Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated atta...
CVE-2022-44456CRITICAL9.8CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS com...
CVE-2022-43486MEDIUM6.8Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative ...
CVE-2022-43466MEDIUM6.8OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative ...
CVE-2022-43443HIGH8.8OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrar...
CVE-2022-41993MEDIUM6.1Cross-site scripting vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated atta...
CVE-2022-4607CRITICAL9.8A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. Thi...
CVE-2022-4605MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2022-4606CRITICAL9.8PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2022-4604HIGH8.8A vulnerability classified as problematic was found in wp-english-wp-admin Plugin up to 1.5.1. Affected by this vulnerab...
CVE-2022-4603MEDIUM6.5A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pp...
CVE-2022-4602MEDIUM5.4A vulnerability was found in Shoplazza LifeStyle 1.1. It has been rated as problematic. This issue affects some unknown ...
CVE-2022-4601MEDIUM5.4A vulnerability was found in Shoplazza LifeStyle 1.1. It has been declared as problematic. This vulnerability affects un...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now