2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43485 | MEDIUM | 6.5 | 0.5% | May 30, 2023 | Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claim... |
| CVE-2022-45853 | MEDIUM | 6.7 | 0.2% | May 30, 2023 | The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmwar... |
| CVE-2022-4676 | MEDIUM | 5.4 | 0.4% | May 30, 2023 | The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow u... |
| CVE-2022-41766 | MEDIUM | 4.3 | 0.6% | May 29, 2023 | An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an a... |
| CVE-2022-24632 | MEDIUM | 5.3 | 27.2% | May 29, 2023 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f... |
| CVE-2022-24631 | MEDIUM | 5.4 | 42.9% | May 29, 2023 | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenan... |
| CVE-2022-46945 | MEDIUM | 6.5 | 4.1% | May 26, 2023 | Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagV... |
| CVE-2022-39374 | MEDIUM | 6.5 | 0.9% | May 26, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malici... |
| CVE-2022-39335 | MEDIUM | 5 | 0.6% | May 26, 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation A... |
| CVE-2022-45366 | MEDIUM | 6.1 | 0.4% | May 25, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.... |
| CVE-2022-46907 | MEDIUM | 6.1 | 1.2% | May 25, 2023 | A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could... |
| CVE-2022-30025 | MEDIUM | 6.5 | 0.8% | May 24, 2023 | SQL injection in "/Framewrk/Home.jsp" file (POST method) in tCredence Analytics iDEAL Wealth and Funds - 1.0 iallows aut... |
| CVE-2022-42225 | MEDIUM | 5.4 | 0.7% | May 24, 2023 | Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of use... |
| CVE-2022-4945 | MEDIUM | 6.5 | 0.2% | May 22, 2023 | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this spec... |
| CVE-2022-0010 | MEDIUM | 5.5 | 0.2% | May 22, 2023 | Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering... |
| CVE-2022-36328 | MEDIUM | 4.9 | 0.8% | May 18, 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacke... |
| CVE-2022-36326 | MEDIUM | 4.9 | 0.6% | May 18, 2023 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co... |
| CVE-2022-47157 | MEDIUM | 4.8 | 0.4% | May 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 ... |
| CVE-2022-4870 | MEDIUM | 5.3 | 0.4% | May 18, 2023 | In affected versions of Octopus Deploy it is possible to discover network details via error message |
| CVE-2022-45144 | MEDIUM | 6.1 | 0.7% | May 17, 2023 | Algoo Tracim before 4.4.2 allows XSS via HTML file upload. |
| CVE-2022-47393 | MEDIUM | 6.5 | 1.0% | May 15, 2023 | An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vuln... |
| CVE-2022-47392 | MEDIUM | 6.5 | 0.9% | May 15, 2023 | An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce C... |
| CVE-2022-47378 | MEDIUM | 6.5 | 0.9% | May 15, 2023 | Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated ... |
| CVE-2022-22508 | MEDIUM | 4.3 | 0.7% | May 15, 2023 | Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block... |
| CVE-2022-48020 | MEDIUM | 6.1 | 0.6% | May 12, 2023 | Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference par... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now