2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0788CRITICAL9.8The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a param...
CVE-2022-0779MEDIUM6.5The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a...
CVE-2022-21122CRITICAL9.8The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to ...
CVE-2022-1703HIGH8.8Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote ...
CVE-2022-24065CRITICAL9.8The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the co...
CVE-2022-31470MEDIUM6.1An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12...
CVE-2022-30466MEDIUM6.5joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay.
CVE-2022-29620MEDIUM6.5FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOT...
CVE-2022-2022MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository nocodb/nocodb prior to 0.91.7.
CVE-2022-30749HIGH7.8Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart d...
CVE-2022-30748MEDIUM5.5Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.
CVE-2022-30747MEDIUM5.5PendingIntent hijacking vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to access files without ...
CVE-2022-30746HIGH7.5Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely ...
CVE-2022-30745MEDIUM5.5Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files ...
CVE-2022-30744HIGH7.8DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arb...
CVE-2022-30743MEDIUM5.3Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co...
CVE-2022-30742LOW3.3Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta...
CVE-2022-30741LOW3.3Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a...
CVE-2022-30740MEDIUM4.3Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored cr...
CVE-2022-30739MEDIUM4.3Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email ...
CVE-2022-30738MEDIUM4.3Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing scri...
CVE-2022-30737MEDIUM5.3Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
CVE-2022-30736MEDIUM5.3Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of co...
CVE-2022-30735HIGH7.5Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok...
CVE-2022-30734MEDIUM5.3Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now