2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0471 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result... |
| CVE-2022-0447 | MEDIUM | 6.4 | 0.6% | Apr 11, 2022 | The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it ... |
| CVE-2022-0314 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo... |
| CVE-2022-0271 | MEDIUM | 6.1 | 2.2% | Apr 11, 2022 | The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac... |
| CVE-2022-0246 | MEDIUM | 4.9 | 3.4% | Apr 11, 2022 | The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio... |
| CVE-2022-27089 | HIGH | 7.8 | 0.2% | Apr 11, 2022 | In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p... |
| CVE-2022-27088 | HIGH | 7.8 | 0.6% | Apr 11, 2022 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with ... |
| CVE-2022-27041 | HIGH | 7.5 | 1.3% | Apr 11, 2022 | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to i... |
| CVE-2022-26414 | MEDIUM | 5.5 | 0.2% | Apr 11, 2022 | A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware versi... |
| CVE-2022-26413 | HIGH | 8 | 0.7% | Apr 11, 2022 | A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a... |
| CVE-2022-1297 | CRITICAL | 9.1 | 0.8% | Apr 11, 2022 | Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vuln... |
| CVE-2022-1296 | CRITICAL | 9.1 | 0.7% | Apr 11, 2022 | Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnera... |
| CVE-2022-1295 | CRITICAL | 9.8 | 1.2% | Apr 11, 2022 | Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2. |
| CVE-2022-0556 | HIGH | 7.8 | 0.3% | Apr 11, 2022 | A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP... |
| CVE-2022-1252 | CRITICAL | 9.1 | 0.5% | Apr 11, 2022 | Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A... |
| CVE-2022-1045 | MEDIUM | 5.4 | 1.5% | Apr 11, 2022 | Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. |
| CVE-2022-0936 | MEDIUM | 5.4 | 0.6% | Apr 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. |
| CVE-2022-28893 | HIGH | 7.8 | 0.4% | Apr 11, 2022 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the in... |
| CVE-2022-27961 | MEDIUM | 5.4 | 0.4% | Apr 10, 2022 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary ... |
| CVE-2022-27960 | MEDIUM | 5.4 | 0.4% | Apr 10, 2022 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to a... |
| CVE-2022-27958 | MEDIUM | 5.4 | 0.6% | Apr 10, 2022 | Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers t... |
| CVE-2022-27477 | CRITICAL | 9.8 | 1.0% | Apr 10, 2022 | Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit. |
| CVE-2022-27476 | MEDIUM | 6.1 | 0.5% | Apr 10, 2022 | A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbi... |
| CVE-2022-27295 | HIGH | 7.5 | 1.4% | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability ... |
| CVE-2022-27294 | HIGH | 7.5 | 1.4% | Apr 10, 2022 | D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerabili... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now