2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2709MEDIUM4.8The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high priv...
CVE-2022-2567MEDIUM4.8The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could a...
CVE-2022-1591MEDIUM4.3The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its sett...
CVE-2022-1580MEDIUM4.3The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a websit...
CVE-2022-38617HIGH8.8SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at ...
CVE-2022-40778MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to e...
CVE-2022-3235HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0490.
CVE-2022-40775MEDIUM5.5An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields.
CVE-2022-40774MEDIUM5.5An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize.
CVE-2022-40769HIGH7.5profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from...
CVE-2022-25873MEDIUM5.4The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper inp...
CVE-2022-40768MEDIUM5.5drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel me...
CVE-2022-40766CRITICAL9.8Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' subst...
CVE-2022-3234HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
CVE-2022-3232MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5.
CVE-2022-39960MEDIUM5.3The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an...
CVE-2022-3231MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.
CVE-2022-3173MEDIUM4.3Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
CVE-2022-39217CRITICAL9.8some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security...
CVE-2022-39212MEDIUM5.3Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an at...
CVE-2022-39210MEDIUM5.5Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud...
CVE-2022-40300CRITICAL9.8Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager P...
CVE-2022-39211MEDIUM5.3Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webse...
CVE-2022-36027HIGH7.5TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel we...
CVE-2022-36017HIGH7.5TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requeste...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now