2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23005 | HIGH | 8.7 | 0.8% | Jan 23, 2023 | Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulner... |
| CVE-2022-37719 | HIGH | 8.8 | 0.4% | Jan 23, 2023 | A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalat... |
| CVE-2022-37718 | HIGH | 8.8 | 3.5% | Jan 23, 2023 | The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerabil... |
| CVE-2022-38725 | HIGH | 7.5 | 2.4% | Jan 23, 2023 | An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a ... |
| CVE-2022-4746 | HIGH | 7.5 | 0.7% | Jan 23, 2023 | The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over P... |
| CVE-2022-4323 | HIGH | 7.2 | 1.0% | Jan 23, 2023 | The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high... |
| CVE-2022-4303 | HIGH | 7.5 | 0.7% | Jan 23, 2023 | The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers ... |
| CVE-2022-4230 | HIGH | 8.8 | 34.3% | Jan 23, 2023 | The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p... |
| CVE-2022-4017 | HIGH | 8.8 | 0.3% | Jan 23, 2023 | The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, B... |
| CVE-2022-47065 | HIGH | 8.8 | 1.1% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2022-3425 | HIGH | 7.2 | 1.0% | Jan 23, 2023 | The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high... |
| CVE-2022-3918 | HIGH | 8.8 | 0.8% | Jan 20, 2023 | A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URL... |
| CVE-2022-1109 | HIGH | 7.5 | 0.3% | Jan 20, 2023 | An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service. |
| CVE-2022-48279 | HIGH | 7.5 | 1.2% | Jan 20, 2023 | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the W... |
| CVE-2022-47024 | HIGH | 7.8 | 0.3% | Jan 20, 2023 | A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru... |
| CVE-2022-47021 | HIGH | 7.8 | 0.4% | Jan 20, 2023 | A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9... |
| CVE-2022-47012 | HIGH | 7.5 | 0.9% | Jan 20, 2023 | Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21. |
| CVE-2022-45748 | HIGH | 8.8 | 0.7% | Jan 20, 2023 | An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromCha... |
| CVE-2022-38112 | HIGH | 7.5 | 0.4% | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. |
| CVE-2022-47747 | HIGH | 7.5 | 0.8% | Jan 20, 2023 | kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs. |
| CVE-2022-47732 | HIGH | 7.5 | 0.5% | Jan 20, 2023 | In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and downl... |
| CVE-2022-25631 | HIGH | 7.8 | 0.2% | Jan 20, 2023 | Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnera... |
| CVE-2022-48191 | HIGH | 7 | 0.2% | Jan 20, 2023 | A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malic... |
| CVE-2022-20964 | HIGH | 8.8 | 30.6% | Jan 20, 2023 | A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re... |
| CVE-2022-47766 | HIGH | 8.8 | 0.8% | Jan 19, 2023 | PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now