2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29972 | HIGH | 7.8 | 3.7% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift... |
| CVE-2022-29971 | HIGH | 7.8 | 0.3% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena O... |
| CVE-2022-29933 | HIGH | 8.8 | 4.5% | May 9, 2022 | Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the a... |
| CVE-2022-28739 | HIGH | 7.5 | 3.9% | May 9, 2022 | There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occu... |
| CVE-2022-28738 | CRITICAL | 9.8 | 2.6% | May 9, 2022 | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to ... |
| CVE-2022-27412 | CRITICAL | 9.8 | 3.7% | May 9, 2022 | Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. |
| CVE-2022-27308 | MEDIUM | 5.4 | 2.5% | May 9, 2022 | A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar... |
| CVE-2022-28162 | LOW | 3.3 | 0.1% | May 9, 2022 | Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text. |
| CVE-2022-28161 | MEDIUM | 5.5 | 0.2% | May 9, 2022 | An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allo... |
| CVE-2022-27114 | MEDIUM | 5.5 | 0.9% | May 9, 2022 | There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and ... |
| CVE-2022-22481 | MEDIUM | 5.3 | 1.1% | May 9, 2022 | IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web inter... |
| CVE-2022-22319 | MEDIUM | 5.4 | 0.9% | May 9, 2022 | IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could ... |
| CVE-2022-1338 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv... |
| CVE-2022-1303 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h... |
| CVE-2022-1171 | MEDIUM | 6.1 | 0.8% | May 9, 2022 | The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting ... |
| CVE-2022-1104 | MEDIUM | 4.8 | 53.9% | May 9, 2022 | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allo... |
| CVE-2022-1047 | MEDIUM | 6.1 | 0.8% | May 9, 2022 | The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL b... |
| CVE-2022-1013 | CRITICAL | 9.8 | 6.6% | May 9, 2022 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be... |
| CVE-2022-0948 | CRITICAL | 9.8 | 9.8% | May 9, 2022 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before us... |
| CVE-2022-0898 | MEDIUM | 5.4 | 0.6% | May 9, 2022 | The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't hav... |
| CVE-2022-0874 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us... |
| CVE-2022-0836 | CRITICAL | 9.8 | 1.7% | May 9, 2022 | The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL... |
| CVE-2022-0826 | CRITICAL | 9.8 | 9.0% | May 9, 2022 | The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL st... |
| CVE-2022-0817 | CRITICAL | 9.8 | 11.5% | May 9, 2022 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v... |
| CVE-2022-0814 | CRITICAL | 9.8 | 8.9% | May 9, 2022 | The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now