2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31020HIGH8.8Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and...
CVE-2022-26114MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before...
CVE-2022-2714CRITICAL9.8Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.
CVE-2022-2901HIGH7.1Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
CVE-2022-34883HIGH8.8OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users...
CVE-2022-34882MEDIUM6.5Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r...
CVE-2022-34747CRITICAL9.8A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach...
CVE-2022-38367MEDIUM5.3The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an ...
CVE-2022-39838HIGH8.6Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allo...
CVE-2022-31814CRITICAL9.8pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar...
CVE-2022-30331HIGH8.8The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language)...
CVE-2022-3122CRITICAL9.8A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affect...
CVE-2022-3121HIGH8.8A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problem...
CVE-2022-3127MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.
CVE-2022-2775MEDIUM5.5The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow...
CVE-2022-2657MEDIUM4.3The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in...
CVE-2022-2597MEDIUM5.4The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks...
CVE-2022-2565HIGH7.2The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given...
CVE-2022-2543MEDIUM6.1The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks...
CVE-2022-2376MEDIUM5.3The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to bo...
CVE-2022-2271MEDIUM4.8The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privileg...
CVE-2022-2083HIGH7.5The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers...
CVE-2022-2830CRITICAL9.8Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console a...
CVE-2022-3123MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
CVE-2022-38752MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now