2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3993CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.
CVE-2022-38705MEDIUM6.1 IBM CICS TX 11.1 Standard and Advanced could allow a remote attacker to bypass security restrictions, caused by a rever...
CVE-2022-34329MEDIUM5.3 IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 22...
CVE-2022-34319HIGH7.5IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi...
CVE-2022-34313LOW3.1 IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to...
CVE-2022-34312LOW3.3 IBM CICS TX 11.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID:...
CVE-2022-24938HIGH7.5 A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immed...
CVE-2022-24937CRITICAL9.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows ...
CVE-2022-0137MEDIUM5.5A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffe...
CVE-2022-43693HIGH8.8Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for...
CVE-2022-3992MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Sanitization Management System. Affected by this v...
CVE-2022-35719MEDIUM5.5IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be ...
CVE-2022-0324HIGH7.5There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that ...
CVE-2022-45136CRITICAL9.8Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the...
CVE-2022-43342MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add function of Eramba GRC Software c2.8.1 allows attackers to ...
CVE-2022-43288HIGH8.8Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/in...
CVE-2022-3632MEDIUM6.5The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could ...
CVE-2022-3631MEDIUM4.8The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not sanitize and escapes some of its settings, wh...
CVE-2022-3578MEDIUM6.1The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2022-3574CRITICAL9.8The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which co...
CVE-2022-3539MEDIUM4.8The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and es...
CVE-2022-3538MEDIUM6.5The Webmaster Tools Verification WordPress plugin through 1.2 does not have authorisation and CSRF checks when disabling...
CVE-2022-3484MEDIUM6.1The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leadi...
CVE-2022-3477CRITICAL9.8The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordP...
CVE-2022-3469MEDIUM4.8The WP Attachments WordPress plugin before 5.0.5 does not sanitize and escapes some of its settings, which could allow h...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now