2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27936HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323.
CVE-2022-27935HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth.
CVE-2022-27934HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP.
CVE-2022-27933HIGH8.2Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
CVE-2022-27932HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
CVE-2022-27931HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
CVE-2022-27930MEDIUM5.9Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Unive...
CVE-2022-27929HIGH7.5Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP.
CVE-2022-27928HIGH7.5Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol.
CVE-2022-26657HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join.
CVE-2022-26656HIGH8.2Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via On...
CVE-2022-26655HIGH7.5Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a softw...
CVE-2022-26654HIGH7.5Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP.
CVE-2022-25357MEDIUM5.3Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if ...
CVE-2022-31260MEDIUM6.5In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio...
CVE-2022-30550HIGH8.8An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entrie...
CVE-2022-35861HIGH7.8pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working direc...
CVE-2022-32320HIGH8.8A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read...
CVE-2022-2222MEDIUM4.9The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold...
CVE-2022-2194MEDIUM4.8The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing hi...
CVE-2022-2187MEDIUM6.1The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou...
CVE-2022-2186MEDIUM4.8The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege u...
CVE-2022-2173MEDIUM6.1The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th...
CVE-2022-2169MEDIUM4.8The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg...
CVE-2022-2168MEDIUM6.1The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now