2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31020 | HIGH | 8.8 | 1.7% | Sep 6, 2022 | Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and... |
| CVE-2022-26114 | MEDIUM | 6.1 | 0.4% | Sep 6, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before... |
| CVE-2022-2714 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0. |
| CVE-2022-2901 | HIGH | 7.1 | 0.5% | Sep 6, 2022 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. |
| CVE-2022-34883 | HIGH | 8.8 | 1.2% | Sep 6, 2022 | OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users... |
| CVE-2022-34882 | MEDIUM | 6.5 | 0.7% | Sep 6, 2022 | Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r... |
| CVE-2022-34747 | CRITICAL | 9.8 | 1.5% | Sep 6, 2022 | A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach... |
| CVE-2022-38367 | MEDIUM | 5.3 | 0.4% | Sep 5, 2022 | The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an ... |
| CVE-2022-39838 | HIGH | 8.6 | 1.5% | Sep 5, 2022 | Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allo... |
| CVE-2022-31814 | CRITICAL | 9.8 | 86.4% | Sep 5, 2022 | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar... |
| CVE-2022-30331 | HIGH | 8.8 | 0.9% | Sep 5, 2022 | The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language)... |
| CVE-2022-3122 | CRITICAL | 9.8 | 0.6% | Sep 5, 2022 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affect... |
| CVE-2022-3121 | HIGH | 8.8 | 0.2% | Sep 5, 2022 | A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problem... |
| CVE-2022-3127 | MEDIUM | 5.4 | 0.5% | Sep 5, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8. |
| CVE-2022-2775 | MEDIUM | 5.5 | 0.6% | Sep 5, 2022 | The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow... |
| CVE-2022-2657 | MEDIUM | 4.3 | 0.3% | Sep 5, 2022 | The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in... |
| CVE-2022-2597 | MEDIUM | 5.4 | 0.4% | Sep 5, 2022 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks... |
| CVE-2022-2565 | HIGH | 7.2 | 0.6% | Sep 5, 2022 | The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given... |
| CVE-2022-2543 | MEDIUM | 6.1 | 0.5% | Sep 5, 2022 | The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks... |
| CVE-2022-2376 | MEDIUM | 5.3 | 1.4% | Sep 5, 2022 | The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to bo... |
| CVE-2022-2271 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privileg... |
| CVE-2022-2083 | HIGH | 7.5 | 0.6% | Sep 5, 2022 | The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers... |
| CVE-2022-2830 | CRITICAL | 9.8 | 0.8% | Sep 5, 2022 | Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console a... |
| CVE-2022-3123 | MEDIUM | 6.1 | 0.9% | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. |
| CVE-2022-38752 | MEDIUM | 6.5 | 2.0% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now