2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26314CRITICAL9.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix ...
CVE-2022-26313CRITICAL9.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In cert...
CVE-2022-25311HIGH7.3A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SIN...
CVE-2022-24661HIGH7.8A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2022.1). The starview+.exe contains a...
CVE-2022-24408HIGH7.8A vulnerability has been identified in SINUMERIK MC (All versions < V1.15 SP1), SINUMERIK ONE (All versions < V6.15 SP1)...
CVE-2022-24309HIGH8.1A vulnerability has been identified in Mendix Runtime V7 (All versions < V7.23.29), Mendix Runtime V8 (All versions < V8...
CVE-2022-24282HIGH7.2A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SIN...
CVE-2022-24281HIGH7.2A vulnerability has been identified in SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). A privileged...
CVE-2022-24737MEDIUM6.5HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently sto...
CVE-2022-24738HIGH7.4Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are...
CVE-2022-22351HIGH8.6IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nim...
CVE-2022-0756MEDIUM6.5Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0755MEDIUM4.3Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0754MEDIUM6.5SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0535MEDIUM4.8The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-0533MEDIUM6.1The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (X...
CVE-2022-0448MEDIUM4.8The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow h...
CVE-2022-0445MEDIUM6.5The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CS...
CVE-2022-0442MEDIUM4.3The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make su...
CVE-2022-0441CRITICAL9.8The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,...
CVE-2022-0440HIGH7.2The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could...
CVE-2022-0439HIGH8.8The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` pa...
CVE-2022-0434CRITICAL9.8The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it i...
CVE-2022-0429MEDIUM6.1The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable befor...
CVE-2022-0426MEDIUM5.4The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before output...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now