2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42131 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST d... |
| CVE-2022-42130 | MEDIUM | 4.3 | 0.7% | Nov 15, 2022 | The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 bef... |
| CVE-2022-42129 | MEDIUM | 4.3 | 0.7% | Nov 15, 2022 | An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 thro... |
| CVE-2022-40847 | HIGH | 7.8 | 1.0% | Nov 15, 2022 | In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function fo... |
| CVE-2022-40845 | MEDIUM | 6.5 | 0.7% | Nov 15, 2022 | The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined w... |
| CVE-2022-40843 | MEDIUM | 4.9 | 28.8% | Nov 15, 2022 | The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management... |
| CVE-2022-42978 | HIGH | 7.5 | 0.8% | Nov 15, 2022 | In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated a... |
| CVE-2022-42977 | HIGH | 7.5 | 1.0% | Nov 15, 2022 | The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in ... |
| CVE-2022-42128 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check ... |
| CVE-2022-42127 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not prop... |
| CVE-2022-42126 | MEDIUM | 4.3 | 0.8% | Nov 15, 2022 | The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 be... |
| CVE-2022-42125 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through... |
| CVE-2022-42124 | HIGH | 7.5 | 1.2% | Nov 15, 2022 | ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2... |
| CVE-2022-42123 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 be... |
| CVE-2022-42122 | CRITICAL | 9.8 | 0.8% | Nov 15, 2022 | A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through... |
| CVE-2022-42121 | HIGH | 8.8 | 1.1% | Nov 15, 2022 | A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before f... |
| CVE-2022-42120 | CRITICAL | 9.8 | 0.8% | Nov 15, 2022 | A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 befor... |
| CVE-2022-42119 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Port... |
| CVE-2022-42118 | MEDIUM | 6.1 | 1.1% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Lifera... |
| CVE-2022-42111 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4... |
| CVE-2022-42984 | CRITICAL | 9.8 | 0.7% | Nov 15, 2022 | WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter ... |
| CVE-2022-42110 | MEDIUM | 6.1 | 0.6% | Nov 15, 2022 | A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Lifera... |
| CVE-2022-40405 | HIGH | 7.5 | 0.6% | Nov 15, 2022 | WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter... |
| CVE-2022-35613 | HIGH | 8.8 | 0.3% | Nov 15, 2022 | Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF). |
| CVE-2022-33986 | MEDIUM | 6.4 | 0.1% | Nov 15, 2022 | DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. D... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now