2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35958 | — | — | — | Aug 15, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-37458. Reason: This candidate is a reservation d... |
| CVE-2022-35954 | MEDIUM | 5 | 0.6% | Aug 15, 2022 | The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio... |
| CVE-2022-35948 | MEDIUM | 5.3 | 1.2% | Aug 15, 2022 | undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection... |
| CVE-2022-2822 | HIGH | 7.5 | 0.7% | Aug 15, 2022 | An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess us... |
| CVE-2022-2821 | HIGH | 7.5 | 1.1% | Aug 15, 2022 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. |
| CVE-2022-2820 | HIGH | 8.2 | 0.6% | Aug 15, 2022 | Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. |
| CVE-2022-2819 | HIGH | 7.8 | 0.5% | Aug 15, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. |
| CVE-2022-2818 | HIGH | 8.8 | 1.3% | Aug 15, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.... |
| CVE-2022-2814 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Aff... |
| CVE-2022-2813 | HIGH | 7.5 | 0.4% | Aug 15, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is a... |
| CVE-2022-2812 | CRITICAL | 9.8 | 0.7% | Aug 15, 2022 | A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects u... |
| CVE-2022-2811 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unkn... |
| CVE-2022-2535 | MEDIUM | 5.3 | 1.5% | Aug 15, 2022 | The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited ... |
| CVE-2022-2384 | MEDIUM | 4.8 | 0.5% | Aug 15, 2022 | The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing ... |
| CVE-2022-2381 | HIGH | 8.8 | 0.4% | Aug 15, 2022 | The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School ... |
| CVE-2022-2379 | HIGH | 7.5 | 2.8% | Aug 15, 2022 | The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us... |
| CVE-2022-2378 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2022-2354 | HIGH | 7.2 | 1.0% | Aug 15, 2022 | The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the s... |
| CVE-2022-2314 | CRITICAL | 9.8 | 12.4% | Aug 15, 2022 | The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. |
| CVE-2022-2180 | CRITICAL | 9.8 | 1.9% | Aug 15, 2022 | The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any autho... |
| CVE-2022-2152 | MEDIUM | 4.8 | 0.5% | Aug 15, 2022 | The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privile... |
| CVE-2022-2116 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them ba... |
| CVE-2022-35949 | CRITICAL | 9.8 | 1.4% | Aug 12, 2022 | undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forge... |
| CVE-2022-35942 | CRITICAL | 10 | 0.5% | Aug 12, 2022 | Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended fil... |
| CVE-2022-35956 | CRITICAL | 9.8 | 0.5% | Aug 12, 2022 | This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single databa... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now