2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40359 | MEDIUM | 6.1 | 1.3% | Sep 23, 2022 | Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php. |
| CVE-2022-40358 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | An issue was discovered in AjaXplorer 4.2.3, allows attackers to cause cross site scripting vulnerabilities via a crafte... |
| CVE-2022-36944 | CRITICAL | 9.8 | 8.2% | Sep 23, 2022 | Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There i... |
| CVE-2022-36338 | HIGH | 8.2 | 0.4% | Sep 23, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver ... |
| CVE-2022-35721 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to e... |
| CVE-2022-35099 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a stack overflow via ImageStream::getPixel(unsigned char*) at /xpdf/S... |
| CVE-2022-35098 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via GfxICCBasedColorSpace::getDefaultColor(Gfx... |
| CVE-2022-35097 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via FoFiTrueType::writeTTF at /xpdf/FoFiTrue... |
| CVE-2022-35096 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via draw_stroke at /gfxpoly/stroke.c. |
| CVE-2022-35095 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutpu... |
| CVE-2022-35094 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /... |
| CVE-2022-35093 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/St... |
| CVE-2022-35092 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via convert_gfxline at /gfxpoly/convert.c. |
| CVE-2022-35091 | MEDIUM | 5.5 | 0.4% | Sep 23, 2022 | SWFTools commit 772e55a2 was discovered to contain a floating point exception (FPE) via DCTStream::readMCURow() at /xpdf... |
| CVE-2022-34348 | HIGH | 7.1 | 1.4% | Sep 23, 2022 | IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processi... |
| CVE-2022-22423 | MEDIUM | 5.5 | 0.2% | Sep 23, 2022 | IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause ... |
| CVE-2022-40628 | CRITICAL | 9.8 | 1.8% | Sep 23, 2022 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 1... |
| CVE-2022-40215 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in Tabs plugin <= 3.7.1 at WordPress. |
| CVE-2022-40194 | HIGH | 7.5 | 0.7% | Sep 23, 2022 | Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at Wo... |
| CVE-2022-40188 | HIGH | 7.5 | 1.5% | Sep 23, 2022 | Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic... |
| CVE-2022-38742 | CRITICAL | 9.8 | 21.8% | Sep 23, 2022 | Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An at... |
| CVE-2022-38470 | HIGH | 8.8 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress. |
| CVE-2022-38134 | HIGH | 8.8 | 0.8% | Sep 23, 2022 | Authenticated (subscriber+) Broken Access Control vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at W... |
| CVE-2022-36417 | MEDIUM | 6.1 | 0.2% | Sep 23, 2022 | Multiple Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in 3D Tag Cloud plugin <=... |
| CVE-2022-2973 | HIGH | 7.5 | 0.8% | Sep 23, 2022 | MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now