2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0658CRITICAL9.8The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_dat...
CVE-2022-0648MEDIUM6.1The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos par...
CVE-2022-0601MEDIUM6.1The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter be...
CVE-2022-0593MEDIUM6.5The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or a...
CVE-2022-0503MEDIUM6.1The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s paramete...
CVE-2022-0478HIGH8.8The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the pos...
CVE-2022-0449MEDIUM6.1The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in so...
CVE-2022-0399MEDIUM6.1The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_s...
CVE-2022-0327MEDIUM6.1The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter b...
CVE-2022-0321MEDIUM6.1The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting i...
CVE-2022-0254CRITICAL9.8The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby param...
CVE-2022-0248MEDIUM6.1The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact for...
CVE-2022-0230MEDIUM6.1The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outpu...
CVE-2022-0169CRITICAL9.8The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 pa...
CVE-2022-0165MEDIUM6.1The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u...
CVE-2022-0161MEDIUM6.1The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it...
CVE-2022-0147MEDIUM6.1The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outpu...
CVE-2022-24576MEDIUM5.5GPAC 1.0.1 is affected by Use After Free through MP4Box.
CVE-2022-24575HIGH7.8GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box.
CVE-2022-24574MEDIUM5.5GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().
CVE-2022-0946MEDIUM5.4Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-24387HIGH7.2With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, ...
CVE-2022-24386MEDIUM6.1Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
CVE-2022-24385MEDIUM6.5A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: Sm...
CVE-2022-24384MEDIUM6.1Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now