2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28613 | HIGH | 7.5 | 0.9% | May 2, 2022 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus T... |
| CVE-2022-26326 | MEDIUM | 6.1 | 0.3% | May 2, 2022 | Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2 |
| CVE-2022-26325 | MEDIUM | 6.1 | 0.3% | May 2, 2022 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2 |
| CVE-2022-1515 | MEDIUM | 5.5 | 0.7% | May 2, 2022 | A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This is... |
| CVE-2022-1475 | MEDIUM | 5.5 | 0.9% | May 2, 2022 | An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavco... |
| CVE-2022-1378 | CRITICAL | 9.8 | 19.6% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p... |
| CVE-2022-1377 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_r... |
| CVE-2022-1376 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p... |
| CVE-2022-1375 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_s... |
| CVE-2022-1374 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_u... |
| CVE-2022-1372 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog... |
| CVE-2022-1371 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe... |
| CVE-2022-1370 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRE... |
| CVE-2022-1369 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe... |
| CVE-2022-1367 | CRITICAL | 9.8 | 21.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle... |
| CVE-2022-1366 | CRITICAL | 9.8 | 19.6% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle... |
| CVE-2022-1282 | MEDIUM | 6.1 | 0.8% | May 2, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, whi... |
| CVE-2022-1281 | CRITICAL | 9.8 | 23.5% | May 2, 2022 | The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is a... |
| CVE-2022-1273 | HIGH | 7.2 | 1.4% | May 2, 2022 | The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege u... |
| CVE-2022-1269 | MEDIUM | 6.1 | 0.9% | May 2, 2022 | The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in a... |
| CVE-2022-1255 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV da... |
| CVE-2022-1250 | MEDIUM | 6.1 | 0.9% | May 2, 2022 | The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirm... |
| CVE-2022-1239 | HIGH | 8.8 | 1.4% | May 2, 2022 | The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could... |
| CVE-2022-1046 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c... |
| CVE-2022-0952 | HIGH | 8.8 | 12.5% | May 2, 2022 | The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now