2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46863 | MEDIUM | 4.8 | 0.4% | Mar 28, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions... |
| CVE-2022-46855 | MEDIUM | 5.4 | 0.5% | Mar 28, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1.... |
| CVE-2022-46848 | MEDIUM | 5.4 | 0.5% | Mar 28, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager ... |
| CVE-2022-45831 | MEDIUM | 6.1 | 0.4% | Mar 28, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox ... |
| CVE-2022-45825 | MEDIUM | 6.1 | 0.5% | Mar 28, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions. |
| CVE-2022-48361 | MEDIUM | 5.3 | 0.4% | Mar 27, 2023 | The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerabi... |
| CVE-2022-48355 | MEDIUM | 6.5 | 0.2% | Mar 27, 2023 | The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can caus... |
| CVE-2022-48354 | MEDIUM | 6.5 | 0.2% | Mar 27, 2023 | The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cau... |
| CVE-2022-48291 | MEDIUM | 6.5 | 0.2% | Mar 27, 2023 | The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this ... |
| CVE-2022-2237 | MEDIUM | 6.1 | 0.4% | Mar 27, 2023 | A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerab... |
| CVE-2022-46416 | MEDIUM | 5.9 | 0.9% | Mar 27, 2023 | Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address... |
| CVE-2022-46415 | MEDIUM | 5.9 | 0.9% | Mar 27, 2023 | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP addres... |
| CVE-2022-48428 | MEDIUM | 5.4 | 68.0% | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible |
| CVE-2022-48427 | MEDIUM | 5.4 | 1.0% | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible |
| CVE-2022-48429 | MEDIUM | 5.4 | 0.6% | Mar 27, 2023 | In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible |
| CVE-2022-48426 | MEDIUM | 5.4 | 1.1% | Mar 27, 2023 | In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible |
| CVE-2022-47146 | MEDIUM | 6.1 | 0.4% | Mar 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 version... |
| CVE-2022-47924 | MEDIUM | 6.5 | 0.3% | Mar 27, 2023 | An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally insta... |
| CVE-2022-46843 | MEDIUM | 6.1 | 0.4% | Mar 27, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 v... |
| CVE-2022-41354 | MEDIUM | 4.3 | 0.8% | Mar 27, 2023 | An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications... |
| CVE-2022-32199 | MEDIUM | 6.5 | 1.7% | Mar 27, 2023 | db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traver... |
| CVE-2022-42528 | MEDIUM | 5.5 | 0.1% | Mar 24, 2023 | In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local infor... |
| CVE-2022-42500 | MEDIUM | 6.7 | 0.1% | Mar 24, 2023 | In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l... |
| CVE-2022-40208 | MEDIUM | 4.3 | 0.6% | Mar 24, 2023 | In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigat... |
| CVE-2022-20499 | MEDIUM | 5.5 | 0.2% | Mar 24, 2023 | In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to loca... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now