2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-40010MEDIUM5.4Tenda AC6 AC1200 Smart Dual-Band WiFi Router 15.03.06.50_multi was discovered to contain a cross-site scripting (XSS) vu...
CVE-2022-46718MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.7.2 and iPadOS 15.7.2, macOS Ventu...
CVE-2022-46715MEDIUM5.5A logic issue was addressed with improved checks. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to b...
CVE-2022-42860MEDIUM5.5This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Monterey 12....
CVE-2022-42807MEDIUM4.3A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. A user may accident...
CVE-2022-42792MEDIUM5.5This issue was addressed with improved data protection. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be abl...
CVE-2022-47593MEDIUM6.5Auth. (subscriber+) SQL Injection (SQLi) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize plugin <= 1.6.35 ...
CVE-2022-48495MEDIUM5.3Vulnerability of unauthorized access to foreground app information.Successful exploitation of this vulnerability may cau...
CVE-2022-48491MEDIUM5.3Vulnerability of missing authentication on certain HUAWEI phones.Successful exploitation of this vulnerability can lead ...
CVE-2022-48488MEDIUM5.3Vulnerability of bypassing the default desktop security controls.Successful exploitation of this vulnerability may cause...
CVE-2022-48469MEDIUM6.5There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause pa...
CVE-2022-33159MEDIUM6.5IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by ...
CVE-2022-43684MEDIUM6.5ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core...
CVE-2022-42880MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Ali Irani Auto Upload Images plugin <= 3.3 versions allows Stored Cro...
CVE-2022-41327MEDIUM4.4A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2....
CVE-2022-33877MEDIUM5.5An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 ...
CVE-2022-47140MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember plugin <= 4.0.1 versions.
CVE-2022-45827MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GalleryPlugins Video Contest plugin <= 3.2 versions.
CVE-2022-31693MEDIUM5.5VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the V...
CVE-2022-4948MEDIUM4.3The FlyingPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on its AJAX...
CVE-2022-46165MEDIUM5.4Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance...
CVE-2022-40533MEDIUM5.5Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.
CVE-2022-40525MEDIUM5.5Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
CVE-2022-40523MEDIUM5.5Information disclosure in Kernel due to indirect branch misprediction.
CVE-2022-33303MEDIUM5.5Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now