2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20629 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could... |
| CVE-2022-20628 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could... |
| CVE-2022-20627 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could... |
| CVE-2022-29824 | MEDIUM | 6.5 | 3.4% | May 3, 2022 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for i... |
| CVE-2022-24974 | MEDIUM | 5.3 | 0.6% | May 2, 2022 | Links may not be rewritten according to policy in some specially formatted emails. |
| CVE-2022-23722 | MEDIUM | 6.5 | 0.6% | May 2, 2022 | When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Tim... |
| CVE-2022-29444 | MEDIUM | 5.4 | 0.5% | May 2, 2022 | Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPr... |
| CVE-2022-26326 | MEDIUM | 6.1 | 0.3% | May 2, 2022 | Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2 |
| CVE-2022-26325 | MEDIUM | 6.1 | 0.3% | May 2, 2022 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2 |
| CVE-2022-1515 | MEDIUM | 5.5 | 0.7% | May 2, 2022 | A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This is... |
| CVE-2022-1475 | MEDIUM | 5.5 | 0.9% | May 2, 2022 | An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavco... |
| CVE-2022-1282 | MEDIUM | 6.1 | 0.8% | May 2, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, whi... |
| CVE-2022-1269 | MEDIUM | 6.1 | 0.9% | May 2, 2022 | The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in a... |
| CVE-2022-1255 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV da... |
| CVE-2022-1250 | MEDIUM | 6.1 | 0.9% | May 2, 2022 | The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirm... |
| CVE-2022-1046 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c... |
| CVE-2022-0662 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u... |
| CVE-2022-0649 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo... |
| CVE-2022-0428 | MEDIUM | 6.1 | 0.8% | May 2, 2022 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in ... |
| CVE-2022-0418 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege ... |
| CVE-2022-0191 | MEDIUM | 6.5 | 0.5% | May 2, 2022 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic... |
| CVE-2022-23065 | MEDIUM | 5.4 | 0.6% | May 2, 2022 | In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog pe... |
| CVE-2022-29973 | MEDIUM | 4.7 | 0.3% | May 2, 2022 | relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in cert... |
| CVE-2022-29969 | MEDIUM | 6.1 | 0.7% | May 2, 2022 | The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist an... |
| CVE-2022-25349 | MEDIUM | 5.4 | 1.0% | May 1, 2022 | All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user inpu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now