2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2306HIGH7.5Old session tokens can be used to authenticate to the application and send authenticated requests.
CVE-2022-34918HIGH7.8An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff...
CVE-2022-34829HIGH7.5Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload ...
CVE-2022-31603MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned ...
CVE-2022-31602MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a precondit...
CVE-2022-31601MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker t...
CVE-2022-31600HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vu...
CVE-2022-31599HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause acc...
CVE-2022-34265CRITICAL9.8An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions a...
CVE-2022-33171CRITICAL9.8The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input...
CVE-2022-2268HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip...
CVE-2022-1967MEDIUM6.5The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a l...
CVE-2022-1946MEDIUM6.1The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the resp...
CVE-2022-1301MEDIUM4.8The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders...
CVE-2022-0250MEDIUM6.1The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it i...
CVE-2022-2301MEDIUM5.5Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
CVE-2022-2300MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-29892MEDIUM6.5Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker ...
CVE-2022-29513MEDIUM4.8Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker ...
CVE-2022-29484HIGH8.1Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attack...
CVE-2022-29471MEDIUM4.3Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain th...
CVE-2022-29467MEDIUM4.3Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to o...
CVE-2022-28718MEDIUM4.3Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated atta...
CVE-2022-28713MEDIUM5.3Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain s...
CVE-2022-28692MEDIUM4.3Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attac...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now