2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43167 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_aler... |
| CVE-2022-43166 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) o... |
| CVE-2022-43165 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) o... |
| CVE-2022-43164 | MEDIUM | 5.4 | 0.9% | Oct 28, 2022 | A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of ... |
| CVE-2022-3400 | MEDIUM | 6.5 | 0.6% | Oct 28, 2022 | The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav... |
| CVE-2022-39366 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat... |
| CVE-2022-2864 | HIGH | 8.8 | 0.5% | Oct 28, 2022 | The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2022-3697 | HIGH | 7.5 | 0.7% | Oct 28, 2022 | A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2... |
| CVE-2022-39367 | MEDIUM | 6.5 | 1.0% | Oct 28, 2022 | QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine a... |
| CVE-2022-37426 | HIGH | 7.5 | 0.5% | Oct 28, 2022 | Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content... |
| CVE-2022-37425 | CRITICAL | 9.8 | 1.5% | Oct 28, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebu... |
| CVE-2022-37424 | MEDIUM | 6.5 | 0.7% | Oct 28, 2022 | Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. |
| CVE-2022-3018 | MEDIUM | 4.9 | 0.7% | Oct 28, 2022 | An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers... |
| CVE-2022-2882 | MEDIUM | 4.3 | 0.7% | Oct 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start... |
| CVE-2022-43276 | HIGH | 7.2 | 0.7% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p... |
| CVE-2022-43275 | HIGH | 7.2 | 0.9% | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_acti... |
| CVE-2022-3741 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depe... |
| CVE-2022-3512 | HIGH | 8.8 | 0.4% | Oct 28, 2022 | Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" f... |
| CVE-2022-3337 | HIGH | 8.5 | 0.4% | Oct 28, 2022 | It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch... |
| CVE-2022-3322 | HIGH | 7.5 | 0.2% | Oct 28, 2022 | Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab... |
| CVE-2022-3321 | HIGH | 8.2 | 0.4% | Oct 28, 2022 | It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect... |
| CVE-2022-3320 | CRITICAL | 9.8 | 0.4% | Oct 28, 2022 | It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' ... |
| CVE-2022-3735 | CRITICAL | 9.8 | 0.5% | Oct 28, 2022 | A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing o... |
| CVE-2022-3734 | CRITICAL | 9.8 | 0.6% | Oct 28, 2022 | A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unkno... |
| CVE-2022-3733 | HIGH | 8.8 | 0.5% | Oct 28, 2022 | A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now