2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0788 | CRITICAL | 9.8 | 7.9% | Jun 8, 2022 | The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a param... |
| CVE-2022-0779 | MEDIUM | 6.5 | 2.2% | Jun 8, 2022 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a... |
| CVE-2022-21122 | CRITICAL | 9.8 | 2.4% | Jun 8, 2022 | The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to ... |
| CVE-2022-1703 | HIGH | 8.8 | 11.1% | Jun 8, 2022 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote ... |
| CVE-2022-24065 | CRITICAL | 9.8 | 4.2% | Jun 8, 2022 | The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the co... |
| CVE-2022-31470 | MEDIUM | 6.1 | 52.1% | Jun 7, 2022 | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12... |
| CVE-2022-30466 | MEDIUM | 6.5 | 0.7% | Jun 7, 2022 | joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay. |
| CVE-2022-29620 | MEDIUM | 6.5 | 1.7% | Jun 7, 2022 | FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOT... |
| CVE-2022-2022 | MEDIUM | 5.4 | 0.8% | Jun 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7. |
| CVE-2022-30749 | HIGH | 7.8 | 0.2% | Jun 7, 2022 | Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart d... |
| CVE-2022-30748 | MEDIUM | 5.5 | 0.2% | Jun 7, 2022 | Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity. |
| CVE-2022-30747 | MEDIUM | 5.5 | 0.2% | Jun 7, 2022 | PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without ... |
| CVE-2022-30746 | HIGH | 7.5 | 0.8% | Jun 7, 2022 | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely ... |
| CVE-2022-30745 | MEDIUM | 5.5 | 0.2% | Jun 7, 2022 | Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files ... |
| CVE-2022-30744 | HIGH | 7.8 | 0.2% | Jun 7, 2022 | DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arb... |
| CVE-2022-30743 | MEDIUM | 5.3 | 0.4% | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co... |
| CVE-2022-30742 | LOW | 3.3 | 0.2% | Jun 7, 2022 | Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta... |
| CVE-2022-30741 | LOW | 3.3 | 0.2% | Jun 7, 2022 | Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a... |
| CVE-2022-30740 | MEDIUM | 4.3 | 0.2% | Jun 7, 2022 | Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored cr... |
| CVE-2022-30739 | MEDIUM | 4.3 | 0.4% | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email ... |
| CVE-2022-30738 | MEDIUM | 4.3 | 0.5% | Jun 7, 2022 | Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing scri... |
| CVE-2022-30737 | MEDIUM | 5.3 | 0.5% | Jun 7, 2022 | Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID. |
| CVE-2022-30736 | MEDIUM | 5.3 | 0.4% | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co... |
| CVE-2022-30735 | HIGH | 7.5 | 0.4% | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok... |
| CVE-2022-30734 | MEDIUM | 5.3 | 0.5% | Jun 7, 2022 | Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now