2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40100CRITICAL9.8Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.
CVE-2022-3263HIGH7.8The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a loc...
CVE-2022-38704MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 40...
CVE-2022-38454HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Kraken.io Image Optimizer plugin <= 2.6.5 at WordPress.
CVE-2022-38439MEDIUM5.4Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2022-38438MEDIUM5.4Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2022-38079HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability Backup Scheduler plugin <= 1.5.13 at WordPress.
CVE-2022-36340MEDIUM5.3Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
CVE-2022-35893HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the F...
CVE-2022-35251MEDIUM5.4A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an ad...
CVE-2022-35250MEDIUM4.3A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any auth...
CVE-2022-35249MEDIUM4.3A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method...
CVE-2022-35248HIGH8.8A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentic...
CVE-2022-35247MEDIUM4.3A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in th...
CVE-2022-35246MEDIUM4.3A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in t...
CVE-2022-32853HIGH7.1An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-00...
CVE-2022-32852HIGH7.1An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.5. Pr...
CVE-2022-32851HIGH7.1An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-00...
CVE-2022-32849MEDIUM5.5An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 15.6 and iPadO...
CVE-2022-32848MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5. An a...
CVE-2022-32847CRITICAL9.1This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, wa...
CVE-2022-32845CRITICAL10This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monte...
CVE-2022-32843HIGH7.1An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-00...
CVE-2022-32842HIGH7.8An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in Security Update 2022-00...
CVE-2022-32841MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadO...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now