2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0471MEDIUM6.1The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result...
CVE-2022-0447MEDIUM6.4The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it ...
CVE-2022-0314MEDIUM6.1The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo...
CVE-2022-0271MEDIUM6.1The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac...
CVE-2022-0246MEDIUM4.9The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio...
CVE-2022-27089HIGH7.8In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p...
CVE-2022-27088HIGH7.8Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with ...
CVE-2022-27041HIGH7.5Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to i...
CVE-2022-26414MEDIUM5.5A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware versi...
CVE-2022-26413HIGH8A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a...
CVE-2022-1297CRITICAL9.1Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vuln...
CVE-2022-1296CRITICAL9.1Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnera...
CVE-2022-1295CRITICAL9.8Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.
CVE-2022-0556HIGH7.8A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP...
CVE-2022-1252CRITICAL9.1Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A...
CVE-2022-1045MEDIUM5.4Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
CVE-2022-0936MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
CVE-2022-28893HIGH7.8The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the in...
CVE-2022-27961MEDIUM5.4A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary ...
CVE-2022-27960MEDIUM5.4Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to a...
CVE-2022-27958MEDIUM5.4Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers t...
CVE-2022-27477CRITICAL9.8Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
CVE-2022-27476MEDIUM6.1A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbi...
CVE-2022-27295HIGH7.5D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability ...
CVE-2022-27294HIGH7.5D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerabili...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now