2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31753HIGH7.5The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of th...
CVE-2022-31752MEDIUM5.5Missing authorization vulnerability in the system components. Successful exploitation of this vulnerability will affect ...
CVE-2022-31055HIGH7.5kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf clus...
CVE-2022-31763MEDIUM5.5The kernel module has the null pointer and out-of-bounds array vulnerabilities. Successful exploitation of this vulnerab...
CVE-2022-31762HIGH7.8The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privileg...
CVE-2022-31759MEDIUM5.5AppLink has a vulnerability of accessing uninitialized pointers. Successful exploitation of this vulnerability may affec...
CVE-2022-31758MEDIUM4.7The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data co...
CVE-2022-31756MEDIUM5.5The fingerprint sensor module has design defects. Successful exploitation of this vulnerability may affect data confiden...
CVE-2022-31755MEDIUM5.5The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulner...
CVE-2022-31751MEDIUM5.5The kernel emcom module has multi-thread contention. Successful exploitation of this vulnerability may affect system ava...
CVE-2022-30311CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST reque...
CVE-2022-30310CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST reque...
CVE-2022-30309CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POS...
CVE-2022-30308CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST...
CVE-2022-29244HIGH7.5npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a worksp...
CVE-2022-24077HIGH7.8Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
CVE-2022-1969HIGH8.8The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and ...
CVE-2022-1961MEDIUM4.8The Google Tag Manager for WordPress (GTM4WP) plugin is vulnerable to Stored Cross-Site Scripting due to insufficient es...
CVE-2022-1820MEDIUM6.1The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in vers...
CVE-2022-1768HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and param...
CVE-2022-1750MEDIUM4.8The Sticky Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ popup_title' parameter in v...
CVE-2022-1749HIGH8.8The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting...
CVE-2022-1659HIGH7.3Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin register an AJAX action jupiterx_conditional_manager which ca...
CVE-2022-1658MEDIUM5.4Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow arbitrary plugin deletion by any authenticated user, includin...
CVE-2022-1657HIGH8.8Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscribe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now