2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0858 | MEDIUM | 4.7 | 0.8% | Mar 23, 2022 | A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow... |
| CVE-2022-0857 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Updat... |
| CVE-2022-0842 | MEDIUM | 4.9 | 0.7% | Mar 23, 2022 | A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem... |
| CVE-2022-0396 | MEDIUM | 5.3 | 2.6% | Mar 23, 2022 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. S... |
| CVE-2022-25518 | MEDIUM | 6.5 | 0.7% | Mar 22, 2022 | In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with d... |
| CVE-2022-25484 | MEDIUM | 5.5 | 0.6% | Mar 22, 2022 | tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. |
| CVE-2022-21718 | MEDIUM | 5 | 0.9% | Mar 22, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability ... |
| CVE-2022-27090 | MEDIUM | 5.4 | 0.4% | Mar 21, 2022 | Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter. |
| CVE-2022-23350 | MEDIUM | 5.4 | 0.8% | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-23348 | MEDIUM | 5.3 | 3.4% | Mar 21, 2022 | BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes. |
| CVE-2022-0681 | MEDIUM | 6.5 | 0.5% | Mar 21, 2022 | The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which ... |
| CVE-2022-0640 | MEDIUM | 6.1 | 0.9% | Mar 21, 2022 | The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputt... |
| CVE-2022-0628 | MEDIUM | 6.1 | 0.9% | Mar 21, 2022 | The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it bac... |
| CVE-2022-0627 | MEDIUM | 6.1 | 0.8% | Mar 21, 2022 | The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in a... |
| CVE-2022-0616 | MEDIUM | 4.3 | 0.4% | Mar 21, 2022 | The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow a... |
| CVE-2022-0590 | MEDIUM | 4.8 | 0.6% | Mar 21, 2022 | The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allo... |
| CVE-2022-0515 | MEDIUM | 4.3 | 0.4% | Mar 21, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4. |
| CVE-2022-0514 | MEDIUM | 6.5 | 0.9% | Mar 21, 2022 | Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5. |
| CVE-2022-0423 | MEDIUM | 5.4 | 0.6% | Mar 21, 2022 | The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, a... |
| CVE-2022-0364 | MEDIUM | 5.4 | 67.1% | Mar 21, 2022 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p... |
| CVE-2022-26494 | MEDIUM | 4.8 | 0.6% | Mar 21, 2022 | An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a ... |
| CVE-2022-25570 | MEDIUM | 6.5 | 0.8% | Mar 21, 2022 | In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional pass... |
| CVE-2022-1035 | MEDIUM | 5.5 | 0.8% | Mar 21, 2022 | Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-24656 | MEDIUM | 6.1 | 0.7% | Mar 21, 2022 | HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opene... |
| CVE-2022-1004 | MEDIUM | 4.3 | 0.6% | Mar 21, 2022 | Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###Acc... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now