2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34425HIGH7.5Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote atta...
CVE-2022-34402MEDIUM4.9Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker c...
CVE-2022-34334MEDIUM6.5IBM Sterling Partner Engagement Manager 2.0 does not invalidate session after logout which could allow an authenticated ...
CVE-2022-2981MEDIUM4.9The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog fold...
CVE-2022-2891MEDIUM5.9The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could b...
CVE-2022-2823MEDIUM4.8The Slider, Gallery, and Carousel by MetaSlider WordPress plugin before 3.27.9 does not sanitise and escape some of its ...
CVE-2022-2629MEDIUM4.8The Top Bar WordPress plugin before 3.0.4 does not sanitise and escape some of its settings before outputting them in fr...
CVE-2022-2554MEDIUM4.9The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder...
CVE-2022-2448MEDIUM4.8The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high p...
CVE-2022-2350MEDIUM5.3The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its sett...
CVE-2022-20944MEDIUM6.8A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series...
CVE-2022-20920HIGH7.7A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, ...
CVE-2022-20915HIGH7.4A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Softw...
CVE-2022-20870HIGH8.6A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst...
CVE-2022-20864MEDIUM4.6A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalys...
CVE-2022-20837HIGH8.6A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NA...
CVE-2022-20830MEDIUM5.3A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis...
CVE-2022-40257MEDIUM5.4An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a...
CVE-2022-40248MEDIUM5.4An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a...
CVE-2022-39292HIGH7.5Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitiv...
CVE-2022-3442MEDIUM6.1A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unkno...
CVE-2022-26121MEDIUM5.3An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0....
CVE-2022-3438MEDIUM6.1Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
CVE-2022-42725HIGH7.5Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.
CVE-2022-42724MEDIUM4.3app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now