2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0422MEDIUM6.1The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter b...
CVE-2022-0420HIGH7.2The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using...
CVE-2022-0410HIGH8.8The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter ...
CVE-2022-0389MEDIUM4.8The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high...
CVE-2022-0384MEDIUM4.3The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A...
CVE-2022-0349CRITICAL9.8The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ...
CVE-2022-0347MEDIUM6.1The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter...
CVE-2022-0267HIGH7.2The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL st...
CVE-2022-0205MEDIUM5.4The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a ...
CVE-2022-0163MEDIUM6.5The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a...
CVE-2022-0767CRITICAL9.9Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
CVE-2022-0766CRITICAL9.8Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
CVE-2022-0697MEDIUM6.1Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
CVE-2022-0868MEDIUM6.1Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
CVE-2022-0869MEDIUM6.1Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
CVE-2022-26505HIGH7.4A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media file...
CVE-2022-26496CRITICAL9.8In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the...
CVE-2022-26495CRITICAL9.8In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0...
CVE-2022-26490HIGH7.8st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTIO...
CVE-2022-26487Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26143. Reason: This candidate is a reservation d...
CVE-2022-0845CRITICAL9.8Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
CVE-2022-24921HIGH7.5regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression.
CVE-2022-0849MEDIUM5.5Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
CVE-2022-25465HIGH7.8Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling.
CVE-2022-25044HIGH7.8Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now