2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29468 | HIGH | 8.8 | 1.4% | Aug 22, 2022 | A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially... |
| CVE-2022-28712 | CRITICAL | 9 | 2.4% | Aug 22, 2022 | A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master co... |
| CVE-2022-28710 | MEDIUM | 6.5 | 2.3% | Aug 22, 2022 | An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit ... |
| CVE-2022-26842 | CRITICAL | 9.6 | 2.9% | Aug 22, 2022 | A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.... |
| CVE-2022-26061 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-... |
| CVE-2022-25972 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafte... |
| CVE-2022-25942 | HIGH | 7.8 | 0.6% | Aug 22, 2022 | An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted... |
| CVE-2022-1930 | HIGH | 7.5 | 0.8% | Aug 22, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an at... |
| CVE-2022-33932 | MEDIUM | 5.3 | 0.7% | Aug 22, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an unprotect... |
| CVE-2022-32480 | MEDIUM | 6.5 | 0.7% | Aug 22, 2022 | Dell PowerScale OneFS, versions 9.0.0, up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain an insecure... |
| CVE-2022-31238 | MEDIUM | 5.5 | 0.2% | Aug 22, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.2, contain a process in... |
| CVE-2022-31237 | LOW | 3.3 | 0.2% | Aug 22, 2022 | Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permi... |
| CVE-2022-28598 | MEDIUM | 6.1 | 5.0% | Aug 22, 2022 | Frappe ERPNext 12.29.0 is vulnerable to XSS where the software does not neutralize or incorrectly neutralize user-contro... |
| CVE-2022-35583 | CRITICAL | 9.8 | 11.3% | Aug 22, 2022 | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje... |
| CVE-2022-35150 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-37134 | CRITICAL | 9.8 | 21.2% | Aug 22, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrn... |
| CVE-2022-37133 | HIGH | 7.5 | 1.1% | Aug 22, 2022 | D-link DIR-816 A2_v1.10CNB04.img reboots the router without authentication via /goform/doReboot. No authentication is re... |
| CVE-2022-36346 | HIGH | 8.8 | 0.3% | Aug 22, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Max Foundry MaxButtons plugin <= 9.2 at WordPress. |
| CVE-2022-35656 | MEDIUM | 4.5 | 0.3% | Aug 22, 2022 | Pega Platform from 8.3 to 8.7.3 vulnerability may allow authenticated security administrators to alter CSRF settings dir... |
| CVE-2022-35655 | MEDIUM | 6.1 | 0.4% | Aug 22, 2022 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. |
| CVE-2022-35654 | MEDIUM | 6.1 | 0.4% | Aug 22, 2022 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |
| CVE-2022-34858 | CRITICAL | 9.8 | 1.3% | Aug 22, 2022 | Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress. |
| CVE-2022-34857 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr... |
| CVE-2022-34776 | HIGH | 7.5 | 0.4% | Aug 22, 2022 | Tabit - giftcard stealth. Several APIs on the web system display, without authorization, sensitive information such as h... |
| CVE-2022-34775 | HIGH | 7.5 | 0.4% | Aug 22, 2022 | Tabit - Excessive data exposure. Another endpoint mapped by the tiny url, was one for reservation cancellation, containi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now