2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2763 | MEDIUM | 4.8 | 0.6% | Oct 3, 2022 | The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow... |
| CVE-2022-2628 | MEDIUM | 4.8 | 0.5% | Oct 3, 2022 | The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-1480 | — | — | — | Oct 3, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-40922 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a de... |
| CVE-2022-40123 | MEDIUM | 6.5 | 1.0% | Oct 3, 2022 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor... |
| CVE-2022-38817 | HIGH | 7.5 | 2.9% | Oct 3, 2022 | Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitiv... |
| CVE-2022-32173 | MEDIUM | 5.4 | 0.5% | Oct 3, 2022 | In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security rol... |
| CVE-2022-36551 | MEDIUM | 6.5 | 5.1% | Oct 3, 2022 | A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.... |
| CVE-2022-40886 | HIGH | 7.2 | 1.0% | Oct 3, 2022 | DedeCMS 5.7.98 has a file upload vulnerability in the background. |
| CVE-2022-41082 | HIGH | 8 | 100.0% | Oct 3, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-41040 | HIGH | 8.8 | 99.9% | Oct 3, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2022-42004 | HIGH | 7.5 | 2.7% | Oct 2, 2022 | In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeseriali... |
| CVE-2022-42003 | HIGH | 7.5 | 2.8% | Oct 2, 2022 | In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of... |
| CVE-2022-42002 | CRITICAL | 9.1 | 1.0% | Oct 1, 2022 | SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate... |
| CVE-2022-39268 | HIGH | 8.1 | 0.4% | Sep 30, 2022 | ### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did ... |
| CVE-2022-34429 | HIGH | 7.1 | 0.2% | Sep 30, 2022 | Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potential... |
| CVE-2022-34428 | LOW | 2.7 | 0.5% | Sep 30, 2022 | Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adve... |
| CVE-2022-40943 | CRITICAL | 9.8 | 1.0% | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. |
| CVE-2022-40923 | MEDIUM | 6.5 | 0.6% | Sep 30, 2022 | A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a... |
| CVE-2022-40756 | HIGH | 8.8 | 0.7% | Sep 30, 2022 | If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update ... |
| CVE-2022-40341 | HIGH | 8.8 | 1.2% | Sep 30, 2022 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbit... |
| CVE-2022-35156 | CRITICAL | 9.8 | 1.3% | Sep 30, 2022 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /... |
| CVE-2022-35155 | MEDIUM | 6.1 | 2.6% | Sep 30, 2022 | Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s... |
| CVE-2022-20945 | MEDIUM | 6.5 | 0.4% | Sep 30, 2022 | A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow... |
| CVE-2022-20930 | MEDIUM | 6.7 | 0.2% | Sep 30, 2022 | A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possib... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now