2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29468HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially...
CVE-2022-28712CRITICAL9A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master co...
CVE-2022-28710MEDIUM6.5An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit ...
CVE-2022-26842CRITICAL9.6A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11....
CVE-2022-26061HIGH7.8A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-...
CVE-2022-25972HIGH7.8An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafte...
CVE-2022-25942HIGH7.8An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted...
CVE-2022-1930HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an at...
CVE-2022-33932MEDIUM5.3Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotect...
CVE-2022-32480MEDIUM6.5Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure...
CVE-2022-31238MEDIUM5.5Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process in...
CVE-2022-31237LOW3.3Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permi...
CVE-2022-28598MEDIUM6.1Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro...
CVE-2022-35583CRITICAL9.8wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje...
CVE-2022-35150CRITICAL9.8Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-37134CRITICAL9.8D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrn...
CVE-2022-37133HIGH7.5D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is re...
CVE-2022-36346HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress.
CVE-2022-35656MEDIUM4.5Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings dir...
CVE-2022-35655MEDIUM6.1Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
CVE-2022-35654MEDIUM6.1Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2022-34858CRITICAL9.8Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
CVE-2022-34857MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr...
CVE-2022-34776HIGH7.5Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as h...
CVE-2022-34775HIGH7.5Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now