2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44030HIGH7.5Redmine 5.x before 5.0.4 allows downloading of file attachments of any Issue or any Wiki page due to insufficient permis...
CVE-2022-42699HIGH8.8Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
CVE-2022-45833MEDIUM6.5Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
CVE-2022-45829HIGH8.1Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
CVE-2022-45816MEDIUM5.4Auth. Stored Cross-Site Scripting (XSS) vulnerability in GD bbPress Attachments plugin <= 4.3.1 on WordPress.
CVE-2022-41910CRITICAL9.1TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d...
CVE-2022-41902CRITICAL9.1TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d...
CVE-2022-45848MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress.
CVE-2022-45359CRITICAL9.8Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
CVE-2022-42888HIGH8.8Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.
CVE-2022-46333HIGH7.2The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e...
CVE-2022-46332CRITICAL9.6The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln...
CVE-2022-44900CRITICAL9.1A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea...
CVE-2022-23475HIGH8.8daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination...
CVE-2022-4147HIGH7.5Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made...
CVE-2022-46161CRITICAL9.8pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfm...
CVE-2022-46154HIGH7.5Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not p...
CVE-2022-45548HIGH8.8AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
CVE-2022-43867HIGH7.8 IBM Spectrum Scale 5.1.0.1 through 5.1.4.1 could allow a local attacker to execute arbitrary commands in the container....
CVE-2022-43369MEDIUM6.1AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the compo...
CVE-2022-41560MEDIUM6.5The Statement Set Upload via the Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitab...
CVE-2022-41559CRITICAL9.3The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows ...
CVE-2022-34361HIGH7.5 IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decr...
CVE-2022-23472HIGH7.5Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for rand...
CVE-2022-23470HIGH7.5Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now