2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42890 | HIGH | 7.5 | 2.3% | Oct 25, 2022 | A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. T... |
| CVE-2022-41704 | HIGH | 7.5 | 2.1% | Oct 25, 2022 | A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue af... |
| CVE-2022-3395 | HIGH | 8.8 | 0.9% | Oct 25, 2022 | The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a databas... |
| CVE-2022-3394 | HIGH | 7.2 | 1.3% | Oct 25, 2022 | The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with ... |
| CVE-2022-3393 | CRITICAL | 9.8 | 1.3% | Oct 25, 2022 | The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV... |
| CVE-2022-3392 | MEDIUM | 4.8 | 0.6% | Oct 25, 2022 | The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-3391 | MEDIUM | 4.8 | 0.6% | Oct 25, 2022 | The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-3350 | MEDIUM | 4.8 | 0.5% | Oct 25, 2022 | The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could all... |
| CVE-2022-3344 | MEDIUM | 5.5 | 0.2% | Oct 25, 2022 | A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept th... |
| CVE-2022-3335 | HIGH | 7.2 | 1.1% | Oct 25, 2022 | The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which... |
| CVE-2022-3302 | HIGH | 7.2 | 1.0% | Oct 25, 2022 | The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using ... |
| CVE-2022-3300 | HIGH | 7.2 | 1.0% | Oct 25, 2022 | The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it... |
| CVE-2022-3247 | MEDIUM | 6.5 | 0.7% | Oct 25, 2022 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJA... |
| CVE-2022-3246 | HIGH | 8.8 | 1.0% | Oct 25, 2022 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape... |
| CVE-2022-3097 | MEDIUM | 6.5 | 0.3% | Oct 25, 2022 | The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible f... |
| CVE-2022-39837 | MEDIUM | 5.5 | 0.4% | Oct 25, 2022 | An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi... |
| CVE-2022-39836 | MEDIUM | 5.5 | 0.4% | Oct 25, 2022 | An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi... |
| CVE-2022-39351 | MEDIUM | 4.4 | 0.2% | Oct 25, 2022 | Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software ... |
| CVE-2022-39350 | MEDIUM | 5.4 | 0.7% | Oct 25, 2022 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis... |
| CVE-2022-39349 | MEDIUM | 5.5 | 0.3% | Oct 25, 2022 | The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `Shar... |
| CVE-2022-39345 | HIGH | 7.5 | 1.3% | Oct 25, 2022 | Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac... |
| CVE-2022-39342 | CRITICAL | 9.8 | 0.9% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un... |
| CVE-2022-39341 | CRITICAL | 9.8 | 0.9% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un... |
| CVE-2022-39340 | MEDIUM | 5.3 | 0.7% | Oct 25, 2022 | OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali... |
| CVE-2022-39327 | CRITICAL | 9.8 | 3.2% | Oct 25, 2022 | Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulner... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now