2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46381 | MEDIUM | 6.1 | 1.7% | Dec 13, 2022 | Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_templat... |
| CVE-2022-43996 | MEDIUM | 5.4 | 0.5% | Dec 13, 2022 | The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload... |
| CVE-2022-41653 | CRITICAL | 9.8 | 0.7% | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user l... |
| CVE-2022-38355 | MEDIUM | 5.5 | 0.4% | Dec 13, 2022 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to t... |
| CVE-2022-2757 | CRITICAL | 9.1 | 0.7% | Dec 13, 2022 | Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an ... |
| CVE-2022-2660 | HIGH | 7.5 | 0.6% | Dec 13, 2022 | Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k... |
| CVE-2022-4207 | MEDIUM | 5.4 | 0.5% | Dec 13, 2022 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values th... |
| CVE-2022-4171 | HIGH | 7.5 | 0.7% | Dec 13, 2022 | The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and includ... |
| CVE-2022-46404 | CRITICAL | 9.8 | 1.8% | Dec 13, 2022 | A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Ma... |
| CVE-2022-38628 | MEDIUM | 6.1 | 0.9% | Dec 13, 2022 | Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered ... |
| CVE-2022-2951 | HIGH | 7.8 | 0.3% | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerabi... |
| CVE-2022-2950 | HIGH | 7.8 | 0.3% | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerabilit... |
| CVE-2022-2949 | HIGH | 7.8 | 0.3% | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerabilit... |
| CVE-2022-2947 | HIGH | 7.8 | 0.3% | Dec 13, 2022 | Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or wri... |
| CVE-2022-23499 | MEDIUM | 6.1 | 0.4% | Dec 13, 2022 | HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and val... |
| CVE-2022-47213 | HIGH | 7.8 | 0.7% | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2022-47212 | HIGH | 7.8 | 0.7% | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2022-47211 | HIGH | 7.8 | 0.8% | Dec 13, 2022 | Microsoft Office Graphics Remote Code Execution Vulnerability |
| CVE-2022-45005 | CRITICAL | 9.8 | 5.4% | Dec 13, 2022 | IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output func... |
| CVE-2022-44713 | HIGH | 7.5 | 1.5% | Dec 13, 2022 | Microsoft Outlook for Mac Spoofing Vulnerability |
| CVE-2022-44710 | HIGH | 7.8 | 0.6% | Dec 13, 2022 | DirectX Graphics Kernel Elevation of Privilege Vulnerability |
| CVE-2022-44708 | HIGH | 8.3 | 1.9% | Dec 13, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-44707 | MEDIUM | 6.5 | 2.5% | Dec 13, 2022 | Windows Kernel Denial of Service Vulnerability |
| CVE-2022-44704 | HIGH | 7.8 | 0.7% | Dec 13, 2022 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability |
| CVE-2022-44702 | HIGH | 7.8 | 1.4% | Dec 13, 2022 | Windows Terminal Remote Code Execution Vulnerability |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now