2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2763MEDIUM4.8The WP Socializer WordPress plugin before 7.3 does not sanitise and escape some of its Icons settings, which could allow...
CVE-2022-2628MEDIUM4.8The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could a...
CVE-2022-1480Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-40922MEDIUM6.5A vulnerability in the LIEF::MachO::BinaryParser::init_and_parse function of LIEF v0.12.1 allows attackers to cause a de...
CVE-2022-40123MEDIUM6.5mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor...
CVE-2022-38817HIGH7.5Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitiv...
CVE-2022-32173MEDIUM5.4In OrchardCore rc1-11259 to v1.2.2 vulnerable to HTML injection, allow an authenticated user with an editor security rol...
CVE-2022-36551MEDIUM6.5A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5....
CVE-2022-40886HIGH7.2DedeCMS 5.7.98 has a file upload vulnerability in the background.
CVE-2022-41082HIGH8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-41040HIGH8.8Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-42004HIGH7.5In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeseriali...
CVE-2022-42003HIGH7.5In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of...
CVE-2022-42002CRITICAL9.1SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate...
CVE-2022-39268HIGH8.1### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did ...
CVE-2022-34429HIGH7.1Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potential...
CVE-2022-34428LOW2.7Dell Hybrid Client prior to version 1.8 contains a Regular Expression Denial of Service Vulnerability in the UI. An adve...
CVE-2022-40943CRITICAL9.8Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
CVE-2022-40923MEDIUM6.5A vulnerability in the LIEF::MachO::SegmentCommand::virtual_address function of LIEF v0.12.1 allows attackers to cause a...
CVE-2022-40756HIGH8.8If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update ...
CVE-2022-40341HIGH8.8mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbit...
CVE-2022-35156CRITICAL9.8Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /...
CVE-2022-35155MEDIUM6.1Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the s...
CVE-2022-20945MEDIUM6.5A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow...
CVE-2022-20930MEDIUM6.7A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possib...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now