2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2404MEDIUM6.1The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-2352HIGH7.2The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, wh...
CVE-2022-1755MEDIUM5.4The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with ...
CVE-2022-1613MEDIUM5.3The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers ov...
CVE-2022-3301LOW2.4Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-38970MEDIUM6.5ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs ...
CVE-2022-36159HIGH8.8Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the compo...
CVE-2022-36158HIGH8Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which a...
CVE-2022-38553MEDIUM6.1Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulner...
CVE-2022-21797CRITICAL9.8The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Paral...
CVE-2022-21169MEDIUM6.1The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allo...
CVE-2022-41352CRITICAL9.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama...
CVE-2022-41347HIGH7.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the z...
CVE-2022-41343HIGH7.5registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure doe...
CVE-2022-3297HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0579.
CVE-2022-3296HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
CVE-2022-41340HIGH7.5The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signa...
CVE-2022-23464HIGH7.5Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SS...
CVE-2022-23463CRITICAL9.8Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. Discove...
CVE-2022-23461MEDIUM6.1Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vul...
CVE-2022-39242MEDIUM5.3Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the...
CVE-2022-39240MEDIUM5.4MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading...
CVE-2022-36025CRITICAL9.1Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect...
CVE-2022-40122CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40121CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now