2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0423 | MEDIUM | 5.4 | 0.6% | Mar 21, 2022 | The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, a... |
| CVE-2022-0364 | MEDIUM | 5.4 | 67.1% | Mar 21, 2022 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p... |
| CVE-2022-0229 | HIGH | 8.1 | 0.5% | Mar 21, 2022 | The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe... |
| CVE-2022-25766 | HIGH | 8.8 | 33.9% | Mar 21, 2022 | The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs w... |
| CVE-2022-24237 | HIGH | 8.8 | 25.3% | Mar 21, 2022 | The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulner... |
| CVE-2022-24236 | LOW | 3.5 | 0.5% | Mar 21, 2022 | An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed ... |
| CVE-2022-24235 | HIGH | 8.8 | 0.7% | Mar 21, 2022 | A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges... |
| CVE-2022-26960 | CRITICAL | 9.1 | 51.0% | Mar 21, 2022 | connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote... |
| CVE-2022-22394 | HIGH | 8.8 | 2.1% | Mar 21, 2022 | The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by impr... |
| CVE-2022-26494 | MEDIUM | 4.8 | 0.6% | Mar 21, 2022 | An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a ... |
| CVE-2022-25570 | MEDIUM | 6.5 | 0.8% | Mar 21, 2022 | In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional pass... |
| CVE-2022-1035 | MEDIUM | 5.5 | 0.8% | Mar 21, 2022 | Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-24656 | MEDIUM | 6.1 | 0.7% | Mar 21, 2022 | HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opene... |
| CVE-2022-0415 | HIGH | 8.8 | 65.2% | Mar 21, 2022 | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. |
| CVE-2022-1004 | MEDIUM | 4.3 | 0.6% | Mar 21, 2022 | Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###Acc... |
| CVE-2022-0475 | MEDIUM | 5.4 | 0.4% | Mar 21, 2022 | Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code cou... |
| CVE-2022-25505 | CRITICAL | 9.8 | 1.1% | Mar 21, 2022 | Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.ph... |
| CVE-2022-25481 | HIGH | 7.5 | 4.7% | Mar 21, 2022 | ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce... |
| CVE-2022-25462 | HIGH | 7.5 | 0.9% | Mar 20, 2022 | Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attack... |
| CVE-2022-26555 | MEDIUM | 5.4 | 0.4% | Mar 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execut... |
| CVE-2022-26247 | MEDIUM | 5.9 | 0.7% | Mar 20, 2022 | TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability... |
| CVE-2022-26246 | MEDIUM | 6.1 | 0.6% | Mar 20, 2022 | TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mai... |
| CVE-2022-25464 | MEDIUM | 4.8 | 0.4% | Mar 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers... |
| CVE-2022-24125 | HIGH | 8.8 | 2.6% | Mar 20, 2022 | The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send ar... |
| CVE-2022-24126 | CRITICAL | 9.8 | 4.4% | Mar 20, 2022 | A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 all... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now