2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2306 | HIGH | 7.5 | 0.7% | Jul 5, 2022 | Old session tokens can be used to authenticate to the application and send authenticated requests. |
| CVE-2022-34918 | HIGH | 7.8 | 5.1% | Jul 4, 2022 | An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff... |
| CVE-2022-34829 | HIGH | 7.5 | 5.4% | Jul 4, 2022 | Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload ... |
| CVE-2022-31603 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned ... |
| CVE-2022-31602 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a precondit... |
| CVE-2022-31601 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker t... |
| CVE-2022-31600 | HIGH | 8.2 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vu... |
| CVE-2022-31599 | HIGH | 8.2 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause acc... |
| CVE-2022-34265 | CRITICAL | 9.8 | 73.3% | Jul 4, 2022 | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions a... |
| CVE-2022-33171 | CRITICAL | 9.8 | 20.3% | Jul 4, 2022 | The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input... |
| CVE-2022-2268 | HIGH | 7.2 | 1.1% | Jul 4, 2022 | The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip... |
| CVE-2022-1967 | MEDIUM | 6.5 | 0.4% | Jul 4, 2022 | The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a l... |
| CVE-2022-1946 | MEDIUM | 6.1 | 1.3% | Jul 4, 2022 | The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the resp... |
| CVE-2022-1301 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders... |
| CVE-2022-0250 | MEDIUM | 6.1 | 1.3% | Jul 4, 2022 | The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it i... |
| CVE-2022-2301 | MEDIUM | 5.5 | 0.6% | Jul 4, 2022 | Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. |
| CVE-2022-2300 | MEDIUM | 5.4 | 0.5% | Jul 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
| CVE-2022-29892 | MEDIUM | 6.5 | 0.9% | Jul 4, 2022 | Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker ... |
| CVE-2022-29513 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker ... |
| CVE-2022-29484 | HIGH | 8.1 | 1.0% | Jul 4, 2022 | Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attack... |
| CVE-2022-29471 | MEDIUM | 4.3 | 0.7% | Jul 4, 2022 | Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain th... |
| CVE-2022-29467 | MEDIUM | 4.3 | 0.7% | Jul 4, 2022 | Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to o... |
| CVE-2022-28718 | MEDIUM | 4.3 | 0.7% | Jul 4, 2022 | Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated atta... |
| CVE-2022-28713 | MEDIUM | 5.3 | 0.9% | Jul 4, 2022 | Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain s... |
| CVE-2022-28692 | MEDIUM | 4.3 | 0.6% | Jul 4, 2022 | Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now