2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28168HIGH7.5In Brocade SANnav before Brocade SANnav v2.2.0.2 and Brocade SANnav2.1.1.8, encoded scp-server passwords are stored usin...
CVE-2022-28167MEDIUM6.5Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password ...
CVE-2022-28166HIGH7.5In Brocade SANnav version before SANN2.2.0.2 and Brocade SANNav before 2.1.1.8, the implementation of TLS/SSL Server Sup...
CVE-2022-26477HIGH7.5The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable va...
CVE-2022-2140CRITICAL9Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject ar...
CVE-2022-2106LOW2.7Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-leve...
CVE-2022-2088MEDIUM4.9An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartIC...
CVE-2022-2210HIGH7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2022-2218MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.
CVE-2022-2208MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
CVE-2022-2216CRITICAL9.8Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.
CVE-2022-2207HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-2217MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.
CVE-2022-0722HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.
CVE-2022-2041MEDIUM5.4The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with ...
CVE-2022-2040MEDIUM5.4The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a ro...
CVE-2022-1995MEDIUM4.8The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to maliciou...
CVE-2022-1994MEDIUM4.8The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its ...
CVE-2022-1990MEDIUM4.8The Nested Pages WordPress plugin before 3.1.21 does not escape and sanitize the some of its settings, which could allow...
CVE-2022-1977HIGH7.2The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the fil...
CVE-2022-1971MEDIUM4.8The NextCellent Gallery WordPress plugin through 1.9.35 does not sanitise and escape some of its image settings, which c...
CVE-2022-1964MEDIUM5.4The Easy SVG Support WordPress plugin before 3.3.0 does not sanitise uploaded SVG files, which could allow users with a ...
CVE-2022-1960MEDIUM4.3The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow a...
CVE-2022-1953CRITICAL9.1The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerab...
CVE-2022-1916MEDIUM6.1The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store WordPress plugin before 1...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now