2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48946 | MEDIUM | 5.5 | 0.3% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect exten... |
| CVE-2022-4974 | MEDIUM | 6.3 | 0.4% | Oct 16, 2024 | The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request For... |
| CVE-2022-4973 | MEDIUM | 5.4 | 0.5% | Oct 16, 2024 | WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploite... |
| CVE-2022-4972 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev... |
| CVE-2022-4971 | MEDIUM | 6.1 | 15.4% | Oct 16, 2024 | The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter cal... |
| CVE-2022-4534 | MEDIUM | 5.3 | 0.3% | Oct 8, 2024 | The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, ... |
| CVE-2022-4541 | MEDIUM | 6.1 | 0.4% | Sep 26, 2024 | The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value... |
| CVE-2022-49041 | MEDIUM | 4.4 | 0.2% | Sep 26, 2024 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functiona... |
| CVE-2022-49040 | MEDIUM | 4.4 | 0.2% | Sep 26, 2024 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functional... |
| CVE-2022-49039 | MEDIUM | 6.7 | 0.2% | Sep 26, 2024 | Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 al... |
| CVE-2022-49038 | HIGH | 7.8 | 0.2% | Sep 26, 2024 | Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client... |
| CVE-2022-49037 | MEDIUM | 6.5 | 0.5% | Sep 26, 2024 | Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client befo... |
| CVE-2022-43845 | HIGH | 7.5 | 0.4% | Sep 25, 2024 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the fail... |
| CVE-2022-2439 | HIGH | 7.2 | 0.7% | Sep 24, 2024 | The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserializ... |
| CVE-2022-48945 | MEDIUM | 5.5 | 0.2% | Sep 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syz... |
| CVE-2022-4533 | MEDIUM | 5.3 | 0.2% | Sep 19, 2024 | The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including... |
| CVE-2022-25770 | HIGH | 7.5 | 0.3% | Sep 18, 2024 | Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, whic... |
| CVE-2022-25768 | MEDIUM | 6.5 | 0.3% | Sep 18, 2024 | The logic in place to facilitate the update process via the user interface lacks access control to verify if permission ... |
| CVE-2022-25777 | MEDIUM | 6.5 | 0.4% | Sep 18, 2024 | Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses ... |
| CVE-2022-25776 | MEDIUM | 6.5 | 0.4% | Sep 18, 2024 | Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be ... |
| CVE-2022-25775 | HIGH | 7.2 | 0.6% | Sep 18, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports ... |
| CVE-2022-25774 | MEDIUM | 5.4 | 0.4% | Sep 18, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications ... |
| CVE-2022-25769 | CRITICAL | 9.1 | 0.5% | Sep 18, 2024 | ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be... |
| CVE-2022-39068 | MEDIUM | 6.5 | 0.4% | Sep 18, 2024 | There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an a... |
| CVE-2022-3459 | MEDIUM | 5.3 | 0.3% | Sep 14, 2024 | The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and in... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now