2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42131MEDIUM4.8Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST d...
CVE-2022-42130MEDIUM4.3The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 bef...
CVE-2022-42129MEDIUM4.3An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 thro...
CVE-2022-40847HIGH7.8In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function fo...
CVE-2022-40845MEDIUM6.5The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined w...
CVE-2022-40843MEDIUM4.9The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management...
CVE-2022-42978HIGH7.5In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated a...
CVE-2022-42977HIGH7.5The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in ...
CVE-2022-42128MEDIUM5.3The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check ...
CVE-2022-42127MEDIUM5.3The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not prop...
CVE-2022-42126MEDIUM4.3The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 be...
CVE-2022-42125HIGH7.5Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through...
CVE-2022-42124HIGH7.5ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2...
CVE-2022-42123HIGH7.5A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 be...
CVE-2022-42122CRITICAL9.8A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through...
CVE-2022-42121HIGH8.8A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before f...
CVE-2022-42120CRITICAL9.8A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 befor...
CVE-2022-42119MEDIUM5.4Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Port...
CVE-2022-42118MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Lifera...
CVE-2022-42111MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4...
CVE-2022-42984CRITICAL9.8WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter ...
CVE-2022-42110MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Lifera...
CVE-2022-40405HIGH7.5WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter...
CVE-2022-35613HIGH8.8Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-33986MEDIUM6.4DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. D...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now