2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27936 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via H.323. |
| CVE-2022-27935 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via Epic Telehealth. |
| CVE-2022-27934 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via HTTP. |
| CVE-2022-27933 | HIGH | 8.2 | 0.9% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. |
| CVE-2022-27932 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. |
| CVE-2022-27931 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol. |
| CVE-2022-27930 | MEDIUM | 5.9 | 0.8% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Unive... |
| CVE-2022-27929 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via HTTP. |
| CVE-2022-27928 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via the Session Initiation Protocol. |
| CVE-2022-26657 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort via One Touch Join. |
| CVE-2022-26656 | HIGH | 8.2 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to trigger a software abort, and possibly enumerate usernames, via On... |
| CVE-2022-26655 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 has Improper Input Validation. The client API allows remote attackers to trigger a softw... |
| CVE-2022-26654 | HIGH | 7.5 | 1.0% | Jul 17, 2022 | Pexip Infinity before 27.3 allows remote attackers to force a software abort via HTTP. |
| CVE-2022-25357 | MEDIUM | 5.3 | 0.6% | Jul 17, 2022 | Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if ... |
| CVE-2022-31260 | MEDIUM | 6.5 | 1.5% | Jul 17, 2022 | In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio... |
| CVE-2022-30550 | HIGH | 8.8 | 1.7% | Jul 17, 2022 | An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entrie... |
| CVE-2022-35861 | HIGH | 7.8 | 0.3% | Jul 17, 2022 | pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working direc... |
| CVE-2022-32320 | HIGH | 8.8 | 0.4% | Jul 17, 2022 | A Cross-Site Request Forgery (CSRF) in Ferdi through 5.8.1 and Ferdium through 6.0.0-nightly.98 allows attackers to read... |
| CVE-2022-2222 | MEDIUM | 4.9 | 0.9% | Jul 17, 2022 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold... |
| CVE-2022-2194 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing hi... |
| CVE-2022-2187 | MEDIUM | 6.1 | 1.3% | Jul 17, 2022 | The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou... |
| CVE-2022-2186 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege u... |
| CVE-2022-2173 | MEDIUM | 6.1 | 0.7% | Jul 17, 2022 | The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th... |
| CVE-2022-2169 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg... |
| CVE-2022-2168 | MEDIUM | 6.1 | 1.1% | Jul 17, 2022 | The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now