2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35238 | MEDIUM | 5.3 | 0.5% | Sep 23, 2022 | Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress. |
| CVE-2022-23144 | CRITICAL | 9.1 | 0.7% | Sep 23, 2022 | There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers coul... |
| CVE-2022-40869 | CRITICAL | 9.8 | 1.1% | Sep 23, 2022 | Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with ... |
| CVE-2022-40865 | CRITICAL | 9.8 | 1.1% | Sep 23, 2022 | Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the req... |
| CVE-2022-40864 | CRITICAL | 9.8 | 1.1% | Sep 23, 2022 | Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement ... |
| CVE-2022-40862 | CRITICAL | 9.8 | 1.1% | Sep 23, 2022 | Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with ... |
| CVE-2022-40860 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with... |
| CVE-2022-40853 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set |
| CVE-2022-40213 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin ... |
| CVE-2022-40093 | HIGH | 7.2 | 0.9% | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40092 | HIGH | 7.2 | 0.9% | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40091 | HIGH | 7.2 | 0.9% | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-3144 | MEDIUM | 4.8 | 0.6% | Sep 23, 2022 | The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve... |
| CVE-2022-38703 | MEDIUM | 4.8 | 0.4% | Sep 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <=... |
| CVE-2022-38095 | MEDIUM | 4.3 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at... |
| CVE-2022-37339 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 a... |
| CVE-2022-37338 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <... |
| CVE-2022-37330 | MEDIUM | 5.4 | 0.4% | Sep 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPr... |
| CVE-2022-36798 | HIGH | 8.8 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.... |
| CVE-2022-35257 | HIGH | 7.8 | 0.2% | Sep 23, 2022 | A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious a... |
| CVE-2022-35253 | — | — | — | Sep 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-35252 | LOW | 3.7 | 1.8% | Sep 23, 2022 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when l... |
| CVE-2022-30121 | MEDIUM | 6.7 | 0.3% | Sep 23, 2022 | The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only fo... |
| CVE-2022-2937 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Descr... |
| CVE-2022-27492 | HIGH | 7.8 | 0.5% | Sep 23, 2022 | An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now