2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-47377CRITICAL9.8Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege...
CVE-2022-3109HIGH7.5An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return valu...
CVE-2022-4555MEDIUM5.3The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deacti...
CVE-2022-41963LOW3.1BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that ...
CVE-2022-36223MEDIUM6.1In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administra...
CVE-2022-46870MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Zeppelin...
CVE-2022-41962LOW2.7BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect A...
CVE-2022-41961MEDIUM4.3BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6 are subject to Ineffective user bans...
CVE-2022-41960MEDIUM4.3BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3, are subject to Insufficient Verificati...
CVE-2022-46393CRITICAL9.8An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow ...
CVE-2022-46392MEDIUM5.3An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough infor...
CVE-2022-45969CRITICAL9.8Alist v3.4.0 is vulnerable to Directory Traversal,
CVE-2022-45338HIGH7.8An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267...
CVE-2022-40004CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted...
CVE-2022-46634CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p...
CVE-2022-46631CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p...
CVE-2022-4527MEDIUM6.1A vulnerability was found in collective.task up to 3.0.8. It has been classified as problematic. This affects the functi...
CVE-2022-4526MEDIUM6.1A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is som...
CVE-2022-4525MEDIUM6.1A vulnerability has been found in National Sleep Research Resource sleepdata.org up to 58.x and classified as problemati...
CVE-2022-4524MEDIUM6.1A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the functi...
CVE-2022-4523MEDIUM6.1A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processi...
CVE-2022-4522MEDIUM6.1A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code....
CVE-2022-4521MEDIUM6.1A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown pa...
CVE-2022-4520MEDIUM6.1A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue...
CVE-2022-4519MEDIUM4.8The WP User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters in versions up...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now