2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40186CRITICAL9.1An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine wa...
CVE-2022-39197MEDIUM6.1An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att...
CVE-2022-38512MEDIUM6.5The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not c...
CVE-2022-28981HIGH7.5Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote atta...
CVE-2022-28980MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers ...
CVE-2022-28977MEDIUM6.1HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack...
CVE-2022-39975MEDIUM4.3The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before updat...
CVE-2022-35896MEDIUM6An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5...
CVE-2022-28982MEDIUM6.1A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service p...
CVE-2022-28979MEDIUM6.1Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before serv...
CVE-2022-28978MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Port...
CVE-2022-39224HIGH7.8Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection res...
CVE-2022-35895HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly ...
CVE-2022-40217HIGH7.2Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-3233MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-38073MEDIUM5.4Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Supp...
CVE-2022-36390MEDIUM5.4Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar pl...
CVE-2022-36386HIGH7.2Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a...
CVE-2022-36383MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game ...
CVE-2022-36365MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.1...
CVE-2022-28802CRITICAL9.9Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScr...
CVE-2022-40219MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin s...
CVE-2022-3252HIGH7.5Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently deco...
CVE-2022-35621MEDIUM5.3Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e...
CVE-2022-29800MEDIUM4.7A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists bec...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now