2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1610 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1603 | MEDIUM | 4.3 | 0.4% | Jun 20, 2022 | The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, ... |
| CVE-2022-1266 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w... |
| CVE-2022-0663 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text... |
| CVE-2022-31734 | MEDIUM | 6.1 | 0.5% | Jun 20, 2022 | Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerabili... |
| CVE-2022-2130 | MEDIUM | 6.1 | 2.9% | Jun 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17. |
| CVE-2022-26669 | MEDIUM | 6.5 | 1.0% | Jun 20, 2022 | ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inj... |
| CVE-2022-26668 | MEDIUM | 6.5 | 0.8% | Jun 20, 2022 | ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privilege... |
| CVE-2022-21742 | MEDIUM | 6.5 | 0.2% | Jun 20, 2022 | Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API func... |
| CVE-2022-34000 | MEDIUM | 6.5 | 0.8% | Jun 19, 2022 | libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.c... |
| CVE-2022-23071 | MEDIUM | 6.5 | 0.9% | Jun 19, 2022 | In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” fu... |
| CVE-2022-33987 | MEDIUM | 5.3 | 1.9% | Jun 18, 2022 | The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. |
| CVE-2022-21503 | MEDIUM | 4.9 | 0.8% | Jun 17, 2022 | Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allo... |
| CVE-2022-31876 | MEDIUM | 5.3 | 1.2% | Jun 17, 2022 | netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can le... |
| CVE-2022-31875 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/schepro... |
| CVE-2022-31873 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.... |
| CVE-2022-25872 | MEDIUM | 5.3 | 1.0% | Jun 17, 2022 | All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and leng... |
| CVE-2022-21184 | MEDIUM | 5.9 | 0.4% | Jun 17, 2022 | An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise... |
| CVE-2022-32444 | MEDIUM | 6.1 | 2.2% | Jun 17, 2022 | An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t... |
| CVE-2022-32442 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the param... |
| CVE-2022-30607 | MEDIUM | 6.5 | 0.7% | Jun 17, 2022 | IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a ... |
| CVE-2022-31246 | MEDIUM | 5.5 | 0.7% | Jun 17, 2022 | paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR... |
| CVE-2022-2113 | MEDIUM | 5.4 | 0.7% | Jun 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2. |
| CVE-2022-30328 | MEDIUM | 6.5 | 0.4% | Jun 16, 2022 | An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interfa... |
| CVE-2022-30327 | MEDIUM | 6.5 | 0.5% | Jun 16, 2022 | An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacke... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now