2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2404 | MEDIUM | 6.1 | 0.5% | Sep 26, 2022 | The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2022-2352 | HIGH | 7.2 | 1.0% | Sep 26, 2022 | The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, wh... |
| CVE-2022-1755 | MEDIUM | 5.4 | 0.5% | Sep 26, 2022 | The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with ... |
| CVE-2022-1613 | MEDIUM | 5.3 | 0.6% | Sep 26, 2022 | The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers ov... |
| CVE-2022-3301 | LOW | 2.4 | 0.5% | Sep 26, 2022 | Improper Cleanup on Thrown Exception in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-38970 | MEDIUM | 6.5 | 1.0% | Sep 26, 2022 | ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs ... |
| CVE-2022-36159 | HIGH | 8.8 | 0.9% | Sep 26, 2022 | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the compo... |
| CVE-2022-36158 | HIGH | 8 | 1.4% | Sep 26, 2022 | Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which a... |
| CVE-2022-38553 | MEDIUM | 6.1 | 2.3% | Sep 26, 2022 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulner... |
| CVE-2022-21797 | CRITICAL | 9.8 | 1.9% | Sep 26, 2022 | The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Paral... |
| CVE-2022-21169 | MEDIUM | 6.1 | 0.7% | Sep 26, 2022 | The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allo... |
| CVE-2022-41352 | CRITICAL | 9.8 | 95.5% | Sep 26, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama... |
| CVE-2022-41347 | HIGH | 7.8 | 0.4% | Sep 26, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.x and 9.x (e.g., 8.8.15). The Sudo configuration permits the z... |
| CVE-2022-41343 | HIGH | 7.5 | 4.1% | Sep 25, 2022 | registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure doe... |
| CVE-2022-3297 | HIGH | 7.8 | 0.5% | Sep 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. |
| CVE-2022-3296 | HIGH | 7.8 | 0.5% | Sep 25, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. |
| CVE-2022-41340 | HIGH | 7.5 | 0.5% | Sep 24, 2022 | The secp256k1-js package before 1.1.0 for Node.js implements ECDSA without required r and s validation, leading to signa... |
| CVE-2022-23464 | HIGH | 7.5 | 0.6% | Sep 24, 2022 | Nepxion Discovery is a solution for Spring Cloud. Discovery is vulnerable to a potential Server-Side Request Forgery (SS... |
| CVE-2022-23463 | CRITICAL | 9.8 | 1.7% | Sep 24, 2022 | Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. Discove... |
| CVE-2022-23461 | MEDIUM | 6.1 | 0.5% | Sep 24, 2022 | Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vul... |
| CVE-2022-39242 | MEDIUM | 5.3 | 0.6% | Sep 24, 2022 | Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the... |
| CVE-2022-39240 | MEDIUM | 5.4 | 0.6% | Sep 24, 2022 | MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading... |
| CVE-2022-36025 | CRITICAL | 9.1 | 0.8% | Sep 24, 2022 | Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect... |
| CVE-2022-40122 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40121 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now