2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1029 | MEDIUM | 4.8 | 0.8% | Jun 27, 2022 | The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma... |
| CVE-2022-1028 | MEDIUM | 4.8 | 0.5% | Jun 27, 2022 | The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and esca... |
| CVE-2022-1010 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of i... |
| CVE-2022-0875 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s... |
| CVE-2022-0444 | MEDIUM | 4.3 | 0.3% | Jun 27, 2022 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth... |
| CVE-2022-2214 | HIGH | 8.8 | 1.0% | Jun 27, 2022 | A vulnerability was found in SourceCodester Library Management System 1.0. It has been rated as critical. Affected by th... |
| CVE-2022-2213 | MEDIUM | 5.4 | 0.5% | Jun 27, 2022 | A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected... |
| CVE-2022-2212 | HIGH | 8.8 | 0.9% | Jun 27, 2022 | A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected ... |
| CVE-2022-33202 | HIGH | 8.1 | 0.4% | Jun 27, 2022 | Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Clou... |
| CVE-2022-33146 | MEDIUM | 6.1 | 1.4% | Jun 27, 2022 | Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitra... |
| CVE-2022-30932 | — | — | — | Jun 26, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-2206 | HIGH | 7.8 | 1.3% | Jun 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-34495 | MEDIUM | 5.5 | 0.3% | Jun 26, 2022 | rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free. |
| CVE-2022-34494 | MEDIUM | 5.5 | 0.3% | Jun 26, 2022 | rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free. |
| CVE-2022-34491 | — | — | — | Jun 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-29969. Reason: This candidate is a duplicate of ... |
| CVE-2022-29931 | MEDIUM | 6.1 | 0.5% | Jun 25, 2022 | The administration interface of the Raytion Custom Security Manager (Raytion CSM) in Version 7.2.0 allows reflected Cros... |
| CVE-2022-31017 | LOW | 2.6 | 0.5% | Jun 25, 2022 | Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic erro... |
| CVE-2022-31016 | MEDIUM | 6.5 | 0.8% | Jun 25, 2022 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an un... |
| CVE-2022-29168 | MEDIUM | 6.1 | 0.8% | Jun 25, 2022 | Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient e... |
| CVE-2022-24893 | HIGH | 8.8 | 0.5% | Jun 25, 2022 | ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a ... |
| CVE-2022-33128 | CRITICAL | 9.1 | 0.8% | Jun 25, 2022 | RG-EG series gateway EG350 EG_RGOS 11.1(6) was discovered to contain a SQL injection vulnerability via the function get_... |
| CVE-2022-34066 | CRITICAL | 9.8 | 2.0% | Jun 24, 2022 | The Texercise package in PyPI v0.0.1 to v0.0.12 was discovered to contain a code execution backdoor. This vulnerability ... |
| CVE-2022-34065 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Rondolu-YT-Concate package in PyPI v0.1.0 was discovered to contain a code execution backdoor. This vulnerability al... |
| CVE-2022-34064 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | The Zibal package in PyPI v1.0.0 was discovered to contain a code execution backdoor. This vulnerability allows attacker... |
| CVE-2022-34061 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Catly-Translate package in PyPI v0.0.3 to v0.0.5 was discovered to contain a code execution backdoor. This vulnerabi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now