2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42461 | HIGH | 8.8 | 0.6% | Nov 18, 2022 | Broken Access Control vulnerability in miniOrange's Google Authenticator plugin <= 5.6.1 on WordPress. |
| CVE-2022-44820 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transact... |
| CVE-2022-44415 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=. |
| CVE-2022-44414 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=. |
| CVE-2022-44413 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/manage_mechanic.php?id=. |
| CVE-2022-43463 | MEDIUM | 4.8 | 0.4% | Nov 18, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Custom Product Tabs for WooCommerce plugin <= 1.7.9 on... |
| CVE-2022-41840 | CRITICAL | 9.8 | 5.1% | Nov 18, 2022 | Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress. |
| CVE-2022-41805 | MEDIUM | 4.3 | 0.2% | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress. |
| CVE-2022-41781 | CRITICAL | 9.8 | 0.6% | Nov 18, 2022 | Broken Access Control vulnerability in Permalink Manager Lite plugin <= 2.2.20 on WordPress. |
| CVE-2022-41692 | HIGH | 8.8 | 0.5% | Nov 18, 2022 | Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. |
| CVE-2022-41652 | CRITICAL | 9.8 | 0.7% | Nov 18, 2022 | Bypass vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2022-40687 | HIGH | 8.8 | 0.7% | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. |
| CVE-2022-40686 | HIGH | 8.8 | 0.3% | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress. |
| CVE-2022-38974 | MEDIUM | 4.3 | 0.5% | Nov 18, 2022 | Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with sub... |
| CVE-2022-38075 | MEDIUM | 6.1 | 0.2% | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin... |
| CVE-2022-45474 | CRITICAL | 9.8 | 0.9% | Nov 18, 2022 | drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request. |
| CVE-2022-45473 | MEDIUM | 5.5 | 0.3% | Nov 18, 2022 | In drachtio-server 0.8.18, /var/log/drachtio has mode 0777 and drachtio.log has mode 0666. |
| CVE-2022-44379 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service. |
| CVE-2022-44378 | HIGH | 7.2 | 1.0% | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic. |
| CVE-2022-44204 | CRITICAL | 9.8 | 1.2% | Nov 18, 2022 | D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow. |
| CVE-2022-45471 | HIGH | 7.5 | 0.5% | Nov 18, 2022 | In JetBrains Hub before 2022.3.15181 Throttling was missed when sending emails to a particular email address |
| CVE-2022-24038 | MEDIUM | 6.5 | 0.6% | Nov 18, 2022 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated ... |
| CVE-2022-24037 | HIGH | 8.2 | 0.7% | Nov 18, 2022 | Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated... |
| CVE-2022-43308 | HIGH | 7.8 | 0.3% | Nov 18, 2022 | INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via c... |
| CVE-2022-24939 | MEDIUM | 6.5 | 0.3% | Nov 18, 2022 | A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This ca... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now