2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36841 | HIGH | 7.8 | 0.1% | Sep 9, 2022 | A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so lib... |
| CVE-2022-36793 | CRITICAL | 9.1 | 0.7% | Sep 9, 2022 | Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress. |
| CVE-2022-36423 | HIGH | 7.4 | 0.3% | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow... |
| CVE-2022-36422 | LOW | 3.1 | 0.4% | Sep 9, 2022 | Rating increase/decrease via race condition in Lester 'GaMerZ' Chan WP-PostRatings plugin <= 1.89 at WordPress. |
| CVE-2022-36376 | CRITICAL | 9.8 | 0.7% | Sep 9, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress. |
| CVE-2022-36356 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Liam Gladdy / Thirty8 Digital Culture Object p... |
| CVE-2022-36280 | MEDIUM | 5.5 | 0.6% | Sep 9, 2022 | An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU c... |
| CVE-2022-35725 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hans Matzen's wp-forecast plugin <= 7.5 at Wor... |
| CVE-2022-35277 | HIGH | 8.8 | 0.3% | Sep 9, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in GetResponse plugin <= 5.5.20 at WordPress. |
| CVE-2022-35275 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (shop manager+) Reflected Cross-Site Scripting (XSS) vulnerability in AlgolPlus Advanced Order Export For ... |
| CVE-2022-2964 | HIGH | 7.8 | 0.3% | Sep 9, 2022 | A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The ... |
| CVE-2022-2905 | MEDIUM | 5.5 | 0.3% | Sep 9, 2022 | An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call fu... |
| CVE-2022-2526 | CRITICAL | 9.8 | 1.1% | Sep 9, 2022 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream... |
| CVE-2022-26394 | MEDIUM | 5.4 | 0.3% | Sep 9, 2022 | The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker ... |
| CVE-2022-26393 | HIGH | 8.1 | 0.6% | Sep 9, 2022 | The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to... |
| CVE-2022-26392 | MEDIUM | 6.5 | 0.6% | Sep 9, 2022 | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is ... |
| CVE-2022-26390 | MEDIUM | 4.2 | 0.4% | Sep 9, 2022 | The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pum... |
| CVE-2022-38286 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list. |
| CVE-2022-38285 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list. |
| CVE-2022-38284 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. |
| CVE-2022-38283 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. |
| CVE-2022-38282 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list. |
| CVE-2022-38281 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. |
| CVE-2022-38280 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. |
| CVE-2022-38279 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now