2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44030 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permis... |
| CVE-2022-42699 | HIGH | 8.8 | 1.3% | Dec 6, 2022 | Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. |
| CVE-2022-45833 | MEDIUM | 6.5 | 0.8% | Dec 6, 2022 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. |
| CVE-2022-45829 | HIGH | 8.1 | 0.8% | Dec 6, 2022 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. |
| CVE-2022-45816 | MEDIUM | 5.4 | 0.4% | Dec 6, 2022 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress. |
| CVE-2022-41910 | CRITICAL | 9.1 | 0.4% | Dec 6, 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d... |
| CVE-2022-41902 | CRITICAL | 9.1 | 0.4% | Dec 6, 2022 | TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d... |
| CVE-2022-45848 | MEDIUM | 6.1 | 0.4% | Dec 6, 2022 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. |
| CVE-2022-45359 | CRITICAL | 9.8 | 13.5% | Dec 6, 2022 | Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress. |
| CVE-2022-42888 | HIGH | 8.8 | 0.7% | Dec 6, 2022 | Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress. |
| CVE-2022-46333 | HIGH | 7.2 | 1.5% | Dec 6, 2022 | The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e... |
| CVE-2022-46332 | CRITICAL | 9.6 | 0.6% | Dec 6, 2022 | The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln... |
| CVE-2022-44900 | CRITICAL | 9.1 | 2.2% | Dec 6, 2022 | A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea... |
| CVE-2022-23475 | HIGH | 8.8 | 0.5% | Dec 6, 2022 | daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination... |
| CVE-2022-4147 | HIGH | 7.5 | 0.6% | Dec 6, 2022 | Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made... |
| CVE-2022-46161 | CRITICAL | 9.8 | 1.6% | Dec 6, 2022 | pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfm... |
| CVE-2022-46154 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not p... |
| CVE-2022-45548 | HIGH | 8.8 | 0.8% | Dec 6, 2022 | AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. |
| CVE-2022-43867 | HIGH | 7.8 | 0.3% | Dec 6, 2022 | IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container.... |
| CVE-2022-43369 | MEDIUM | 6.1 | 0.5% | Dec 6, 2022 | AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the compo... |
| CVE-2022-41560 | MEDIUM | 6.5 | 0.6% | Dec 6, 2022 | The Statement Set Upload via the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitab... |
| CVE-2022-41559 | CRITICAL | 9.3 | 0.7% | Dec 6, 2022 | The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows ... |
| CVE-2022-34361 | HIGH | 7.5 | 0.4% | Dec 6, 2022 | IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decr... |
| CVE-2022-23472 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for rand... |
| CVE-2022-23470 | HIGH | 7.5 | 0.8% | Dec 6, 2022 | Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now