2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28671 | HIGH | 7.8 | 1.1% | Jul 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.... |
| CVE-2022-28670 | HIGH | 7.8 | 1.0% | Jul 18, 2022 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read... |
| CVE-2022-28669 | HIGH | 7.8 | 1.1% | Jul 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.... |
| CVE-2022-26120 | HIGH | 8.8 | 0.6% | Jul 18, 2022 | Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] i... |
| CVE-2022-26118 | MEDIUM | 6.7 | 0.3% | Jul 18, 2022 | A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 ... |
| CVE-2022-26117 | HIGH | 8.8 | 0.9% | Jul 18, 2022 | An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.... |
| CVE-2022-23438 | MEDIUM | 6.1 | 0.5% | Jul 18, 2022 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiO... |
| CVE-2022-22445 | MEDIUM | 6.5 | 0.6% | Jul 18, 2022 | An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise pa... |
| CVE-2022-32387 | HIGH | 7.5 | 0.9% | Jul 18, 2022 | In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler. |
| CVE-2022-2444 | HIGH | 8.8 | 1.8% | Jul 18, 2022 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust... |
| CVE-2022-2443 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin... |
| CVE-2022-2437 | CRITICAL | 9.8 | 1.3% | Jul 18, 2022 | The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untru... |
| CVE-2022-2435 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1... |
| CVE-2022-2224 | MEDIUM | 4.3 | 0.3% | Jul 18, 2022 | The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2022-2223 | MEDIUM | 4.3 | 0.3% | Jul 18, 2022 | The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 d... |
| CVE-2022-2117 | MEDIUM | 5.3 | 0.9% | Jul 18, 2022 | The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20... |
| CVE-2022-2108 | MEDIUM | 5.3 | 0.7% | Jul 18, 2022 | The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and rev... |
| CVE-2022-2101 | MEDIUM | 5.4 | 0.8% | Jul 18, 2022 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter... |
| CVE-2022-2039 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu... |
| CVE-2022-2001 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2022-23745 | HIGH | 7.5 | 14.9% | Jul 18, 2022 | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could resul... |
| CVE-2022-22304 | MEDIUM | 6.1 | 0.5% | Jul 18, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent fo... |
| CVE-2022-1912 | HIGH | 8.8 | 0.5% | Jul 18, 2022 | The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2022-1565 | HIGH | 7.2 | 11.3% | Jul 18, 2022 | The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo... |
| CVE-2022-35741 | CRITICAL | 9.8 | 6.7% | Jul 18, 2022 | Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vul... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now