2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41554 | MEDIUM | 5.4 | 0.4% | Mar 16, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions. |
| CVE-2022-40699 | MEDIUM | 6.1 | 0.4% | Mar 16, 2023 | Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions. |
| CVE-2022-38971 | MEDIUM | 5.4 | 0.4% | Mar 16, 2023 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Prof... |
| CVE-2022-46773 | MEDIUM | 6.5 | 0.5% | Mar 15, 2023 | IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential ... |
| CVE-2022-46774 | MEDIUM | 6.5 | 0.3% | Mar 15, 2023 | IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permission... |
| CVE-2022-43874 | MEDIUM | 6.1 | 0.4% | Mar 15, 2023 | IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-si... |
| CVE-2022-37402 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions. |
| CVE-2022-34148 | MEDIUM | 4.8 | 0.4% | Mar 15, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JetBackup JetBacku... |
| CVE-2022-45155 | MEDIUM | 5.5 | 0.2% | Mar 15, 2023 | An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attack... |
| CVE-2022-23791 | MEDIUM | 6.1 | 0.4% | Mar 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software ... |
| CVE-2022-23790 | MEDIUM | 6.1 | 0.4% | Mar 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firmanet Software ... |
| CVE-2022-47595 | MEDIUM | 6.5 | 0.8% | Mar 14, 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP ... |
| CVE-2022-47171 | MEDIUM | 4.8 | 0.4% | Mar 14, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul C. Schroeder ... |
| CVE-2022-4661 | MEDIUM | 5.4 | 0.5% | Mar 13, 2023 | The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its... |
| CVE-2022-4652 | MEDIUM | 5.4 | 0.5% | Mar 13, 2023 | The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4466 | MEDIUM | 5.4 | 0.5% | Mar 13, 2023 | The WordPress Infinite Scroll WordPress plugin before 5.6.0.3 does not validate and escape some of its shortcode attribu... |
| CVE-2022-2259 | MEDIUM | 4.3 | 0.4% | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned p... |
| CVE-2022-2258 | MEDIUM | 4.3 | 0.5% | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permi... |
| CVE-2022-47484 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone servi... |
| CVE-2022-47483 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone servi... |
| CVE-2022-47482 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone servi... |
| CVE-2022-47481 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone servi... |
| CVE-2022-47480 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone servi... |
| CVE-2022-47479 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit... |
| CVE-2022-47478 | MEDIUM | 5.5 | 0.1% | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no addit... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now