2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2709 | MEDIUM | 4.8 | 0.5% | Sep 19, 2022 | The Float to Top Button WordPress plugin through 2.3.6 does not escape some of its settings, which could allow high priv... |
| CVE-2022-2567 | MEDIUM | 4.8 | 0.5% | Sep 19, 2022 | The Form Builder CP WordPress plugin before 1.2.32 does not sanitise and escape some of its form settings, which could a... |
| CVE-2022-1591 | MEDIUM | 4.3 | 0.3% | Sep 19, 2022 | The WordPress Ping Optimizer WordPress plugin before 2.35.1.3.0 does not have CSRF check in place when updating its sett... |
| CVE-2022-1580 | MEDIUM | 4.3 | 1.3% | Sep 19, 2022 | The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a websit... |
| CVE-2022-38617 | HIGH | 8.8 | 0.9% | Sep 19, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the voiceAudit:j_id97 parameter at ... |
| CVE-2022-40778 | MEDIUM | 5.4 | 0.4% | Sep 19, 2022 | A stored Cross-Site Scripting (XSS) vulnerability in OPSWAT MetaDefender ICAP Server before 4.13.0 allows attackers to e... |
| CVE-2022-3235 | HIGH | 7.8 | 0.5% | Sep 18, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0490. |
| CVE-2022-40775 | MEDIUM | 5.5 | 0.3% | Sep 18, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_StszAtom::WriteFields. |
| CVE-2022-40774 | MEDIUM | 5.5 | 0.3% | Sep 18, 2022 | An issue was discovered in Bento4 through 1.6.0-639. There is a NULL pointer dereference in AP4_StszAtom::GetSampleSize. |
| CVE-2022-40769 | HIGH | 7.5 | 1.0% | Sep 18, 2022 | profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from... |
| CVE-2022-25873 | MEDIUM | 5.4 | 0.6% | Sep 18, 2022 | The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper inp... |
| CVE-2022-40768 | MEDIUM | 5.5 | 0.3% | Sep 18, 2022 | drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel me... |
| CVE-2022-40766 | CRITICAL | 9.8 | 0.8% | Sep 18, 2022 | Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' subst... |
| CVE-2022-3234 | HIGH | 7.8 | 0.5% | Sep 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. |
| CVE-2022-3232 | MEDIUM | 4.3 | 0.3% | Sep 17, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.5. |
| CVE-2022-39960 | MEDIUM | 5.3 | 25.7% | Sep 17, 2022 | The Netic Group Export add-on before 1.0.3 for Atlassian Jira does not perform authorization checks. This might allow an... |
| CVE-2022-3231 | MEDIUM | 5.4 | 0.5% | Sep 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0. |
| CVE-2022-3173 | MEDIUM | 4.3 | 0.7% | Sep 17, 2022 | Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10. |
| CVE-2022-39217 | CRITICAL | 9.8 | 0.5% | Sep 17, 2022 | some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security... |
| CVE-2022-39212 | MEDIUM | 5.3 | 0.5% | Sep 17, 2022 | Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an at... |
| CVE-2022-39210 | MEDIUM | 5.5 | 0.3% | Sep 17, 2022 | Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud... |
| CVE-2022-40300 | CRITICAL | 9.8 | 99.3% | Sep 16, 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager P... |
| CVE-2022-39211 | MEDIUM | 5.3 | 0.7% | Sep 16, 2022 | Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webse... |
| CVE-2022-36027 | HIGH | 7.5 | 0.6% | Sep 16, 2022 | TensorFlow is an open source platform for machine learning. When converting transposed convolutions using per-channel we... |
| CVE-2022-36017 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | TensorFlow is an open source platform for machine learning. If `Requantize` is given `input_min`, `input_max`, `requeste... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now