2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3462MEDIUM4.8The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3451MEDIUM4.3The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple A...
CVE-2022-3418HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allo...
CVE-2022-2711HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in upload...
CVE-2022-2387MEDIUM4.3The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, ...
CVE-2022-44797CRITICAL9.8btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witn...
CVE-2022-44796CRITICAL9.8An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows get...
CVE-2022-44795MEDIUM6.5An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lea...
CVE-2022-44794HIGH8.8An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote...
CVE-2022-44793MEDIUM6.5handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Excepti...
CVE-2022-44792MEDIUM6.5handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug...
CVE-2022-42919HIGH7.8Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configur...
CVE-2022-42905CRITICAL9.1In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 cl...
CVE-2022-37710HIGH7.8Patterson Dental Eaglesoft 21 has AES-256 encryption but there are two ways to obtain a keyfile: (1) keybackup.data > Li...
CVE-2022-40284HIGH7.8A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution...
CVE-2022-44544CRITICAL9.8Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PD...
CVE-2022-42707HIGH7.5In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images ar...
CVE-2022-3869MEDIUM6.1Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
CVE-2022-3868CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an u...
CVE-2022-43572MEDIUM6.5In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S...
CVE-2022-43570MEDIUM6.5In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup lan...
CVE-2022-43569MEDIUM5.4In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scrip...
CVE-2022-43568MEDIUM6.1In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via Jav...
CVE-2022-43567HIGH8.8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system c...
CVE-2022-43566HIGH8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now