2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1472 | HIGH | 7.2 | 1.2% | Jun 20, 2022 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parame... |
| CVE-2022-1266 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w... |
| CVE-2022-0663 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text... |
| CVE-2022-31734 | MEDIUM | 6.1 | 0.5% | Jun 20, 2022 | Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerabili... |
| CVE-2022-2130 | MEDIUM | 6.1 | 2.9% | Jun 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17. |
| CVE-2022-26669 | MEDIUM | 6.5 | 1.0% | Jun 20, 2022 | ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inj... |
| CVE-2022-26668 | MEDIUM | 6.5 | 0.8% | Jun 20, 2022 | ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privilege... |
| CVE-2022-21742 | MEDIUM | 6.5 | 0.2% | Jun 20, 2022 | Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API func... |
| CVE-2022-2023 | CRITICAL | 9.8 | 3.0% | Jun 20, 2022 | Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4. |
| CVE-2022-1836 | — | — | — | Jun 19, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-33981. Reason: This candidate is a reservation d... |
| CVE-2022-34006 | HIGH | 7.8 | 0.3% | Jun 19, 2022 | An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019... |
| CVE-2022-34005 | CRITICAL | 9.8 | 1.6% | Jun 19, 2022 | An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a har... |
| CVE-2022-34000 | MEDIUM | 6.5 | 0.8% | Jun 19, 2022 | libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.c... |
| CVE-2022-2129 | HIGH | 7.8 | 1.3% | Jun 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2126 | HIGH | 7.8 | 1.5% | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2125 | HIGH | 7.8 | 1.6% | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-23071 | MEDIUM | 6.5 | 0.9% | Jun 19, 2022 | In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” fu... |
| CVE-2022-2124 | HIGH | 7.8 | 1.5% | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-33987 | MEDIUM | 5.3 | 1.9% | Jun 18, 2022 | The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket. |
| CVE-2022-33981 | LOW | 3.3 | 0.5% | Jun 18, 2022 | drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency ... |
| CVE-2022-21503 | MEDIUM | 4.9 | 0.8% | Jun 17, 2022 | Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allo... |
| CVE-2022-31876 | MEDIUM | 5.3 | 1.2% | Jun 17, 2022 | netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can le... |
| CVE-2022-31875 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/schepro... |
| CVE-2022-31874 | CRITICAL | 9.8 | 18.7% | Jun 17, 2022 | ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface... |
| CVE-2022-31873 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now