2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24187 | HIGH | 7.5 | 0.7% | Nov 28, 2022 | The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object... |
| CVE-2022-46147 | MEDIUM | 6.1 | 0.8% | Nov 28, 2022 | Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target... |
| CVE-2022-45921 | HIGH | 7.5 | 0.7% | Nov 28, 2022 | FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. ... |
| CVE-2022-45442 | HIGH | 8.8 | 0.6% | Nov 28, 2022 | Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 befo... |
| CVE-2022-44937 | MEDIUM | 6.5 | 0.3% | Nov 28, 2022 | Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrato... |
| CVE-2022-41965 | MEDIUM | 6.1 | 0.3% | Nov 28, 2022 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open... |
| CVE-2022-38140 | HIGH | 8.8 | 0.7% | Nov 28, 2022 | Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. |
| CVE-2022-34654 | HIGH | 8.8 | 0.3% | Nov 28, 2022 | Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress. |
| CVE-2022-4104 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compressio... |
| CVE-2022-4169 | MEDIUM | 5.3 | 0.7% | Nov 28, 2022 | The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.... |
| CVE-2022-41732 | MEDIUM | 5.5 | 0.2% | Nov 28, 2022 | IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Forc... |
| CVE-2022-44399 | CRITICAL | 9.8 | 0.8% | Nov 28, 2022 | Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/c... |
| CVE-2022-44401 | CRITICAL | 9.8 | 0.9% | Nov 28, 2022 | Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. |
| CVE-2022-44400 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. |
| CVE-2022-44284 | MEDIUM | 5.4 | 0.5% | Nov 28, 2022 | Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-44283 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | AVS Audio Converter 10.3 is vulnerable to Buffer Overflow. |
| CVE-2022-41957 | HIGH | 7.5 | 0.9% | Nov 28, 2022 | Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara... |
| CVE-2022-41944 | MEDIUM | 4.3 | 0.4% | Nov 28, 2022 | Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr... |
| CVE-2022-41921 | MEDIUM | 4.3 | 0.5% | Nov 28, 2022 | Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim... |
| CVE-2022-41912 | CRITICAL | 9.8 | 2.2% | Nov 28, 2022 | The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML respon... |
| CVE-2022-31877 | HIGH | 8.8 | 0.4% | Nov 28, 2022 | An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a c... |
| CVE-2022-3865 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
| CVE-2022-3850 | MEDIUM | 4.3 | 0.3% | Nov 28, 2022 | The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow a... |
| CVE-2022-3849 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
| CVE-2022-3848 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now