2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1546 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before ... |
| CVE-2022-1474 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in... |
| CVE-2022-1220 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admi... |
| CVE-2022-1057 | CRITICAL | 9.8 | 6.7% | Jul 11, 2022 | The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter be... |
| CVE-2022-30792 | HIGH | 7.5 | 0.8% | Jul 11, 2022 | In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized atta... |
| CVE-2022-30791 | HIGH | 7.5 | 0.8% | Jul 11, 2022 | In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker... |
| CVE-2022-2302 | CRITICAL | 9.8 | 1.6% | Jul 11, 2022 | Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been lo... |
| CVE-2022-1794 | MEDIUM | 5.5 | 0.2% | Jul 11, 2022 | The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is vi... |
| CVE-2022-29926 | — | — | — | Jul 11, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-2368 | CRITICAL | 9.8 | 0.9% | Jul 11, 2022 | Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20. |
| CVE-2022-35416 | MEDIUM | 6.1 | 2.6% | Jul 11, 2022 | H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS. |
| CVE-2022-32294 | CRITICAL | 9.8 | 2.0% | Jul 11, 2022 | Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ... |
| CVE-2022-35414 | HIGH | 8.8 | 0.6% | Jul 11, 2022 | softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_r... |
| CVE-2022-31588 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_f... |
| CVE-2022-31587 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Fl... |
| CVE-2022-31586 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because t... |
| CVE-2022-31585 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Fla... |
| CVE-2022-31584 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_fil... |
| CVE-2022-31583 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because t... |
| CVE-2022-31582 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_fi... |
| CVE-2022-31581 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file fu... |
| CVE-2022-31580 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flas... |
| CVE-2022-31579 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_fil... |
| CVE-2022-31578 | HIGH | 7.5 | 1.1% | Jul 11, 2022 | The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_fi... |
| CVE-2022-31577 | CRITICAL | 9.3 | 1.1% | Jul 11, 2022 | The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the F... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now