2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45065 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 vers... |
| CVE-2022-45812 | MEDIUM | 5.4 | 0.4% | May 8, 2023 | Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Lees Exxp plugin <= 2.6.8 versions. |
| CVE-2022-46799 | MEDIUM | 6.1 | 0.4% | May 8, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form p... |
| CVE-2022-43877 | MEDIUM | 5.1 | 0.2% | May 6, 2023 | IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of ... |
| CVE-2022-43866 | MEDIUM | 5.4 | 0.4% | May 5, 2023 | IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2022-43919 | MEDIUM | 6.5 | 0.7% | May 5, 2023 | IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages t... |
| CVE-2022-38707 | MEDIUM | 5.5 | 0.2% | May 5, 2023 | IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient sess... |
| CVE-2022-47449 | MEDIUM | 6.1 | 0.4% | May 4, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommer... |
| CVE-2022-47434 | MEDIUM | 4.8 | 0.4% | May 4, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions. |
| CVE-2022-45818 | MEDIUM | 5.4 | 0.4% | May 4, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner U... |
| CVE-2022-4376 | MEDIUM | 4.3 | 0.8% | May 3, 2023 | An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.... |
| CVE-2022-45859 | MEDIUM | 4.4 | 0.1% | May 3, 2023 | An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and... |
| CVE-2022-43950 | MEDIUM | 4.7 | 0.4% | May 3, 2023 | A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC vers... |
| CVE-2022-39161 | MEDIUM | 5.3 | 0.4% | May 3, 2023 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to co... |
| CVE-2022-46852 | MEDIUM | 4.8 | 0.4% | May 3, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions. |
| CVE-2022-43681 | MEDIUM | 6.5 | 2.1% | May 3, 2023 | An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message t... |
| CVE-2022-40318 | MEDIUM | 6.5 | 2.0% | May 3, 2023 | An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x... |
| CVE-2022-40302 | MEDIUM | 6.5 | 2.0% | May 3, 2023 | An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x... |
| CVE-2022-47877 | MEDIUM | 5.4 | 2.6% | May 2, 2023 | A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web... |
| CVE-2022-47874 | MEDIUM | 6.5 | 22.7% | May 2, 2023 | Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat... |
| CVE-2022-33273 | MEDIUM | 5.5 | 0.1% | May 2, 2023 | Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. |
| CVE-2022-48186 | MEDIUM | 6.2 | 0.3% | May 1, 2023 | A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclos... |
| CVE-2022-45801 | MEDIUM | 5.4 | 1.1% | May 1, 2023 | Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web ba... |
| CVE-2022-43871 | MEDIUM | 5.4 | 0.4% | Apr 29, 2023 | IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2022-31643 | MEDIUM | 5.5 | 0.2% | Apr 28, 2023 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow los... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now