2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0422 | MEDIUM | 6.1 | 8.1% | Mar 7, 2022 | The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter b... |
| CVE-2022-0420 | HIGH | 7.2 | 1.5% | Mar 7, 2022 | The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using... |
| CVE-2022-0410 | HIGH | 8.8 | 1.3% | Mar 7, 2022 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter ... |
| CVE-2022-0389 | MEDIUM | 4.8 | 0.6% | Mar 7, 2022 | The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high... |
| CVE-2022-0384 | MEDIUM | 4.3 | 1.0% | Mar 7, 2022 | The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A... |
| CVE-2022-0349 | CRITICAL | 9.8 | 34.4% | Mar 7, 2022 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ... |
| CVE-2022-0347 | MEDIUM | 6.1 | 0.8% | Mar 7, 2022 | The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter... |
| CVE-2022-0267 | HIGH | 7.2 | 1.3% | Mar 7, 2022 | The AdRotate WordPress plugin before 5.8.22 does not sanitise and escape the adrotate_action before using it in a SQL st... |
| CVE-2022-0205 | MEDIUM | 5.4 | 0.6% | Mar 7, 2022 | The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a ... |
| CVE-2022-0163 | MEDIUM | 6.5 | 1.0% | Mar 7, 2022 | The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a... |
| CVE-2022-0767 | CRITICAL | 9.9 | 1.0% | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. |
| CVE-2022-0766 | CRITICAL | 9.8 | 1.3% | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. |
| CVE-2022-0697 | MEDIUM | 6.1 | 0.6% | Mar 6, 2022 | Open Redirect in GitHub repository archivy/archivy prior to 1.7.0. |
| CVE-2022-0868 | MEDIUM | 6.1 | 0.7% | Mar 6, 2022 | Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. |
| CVE-2022-0869 | MEDIUM | 6.1 | 2.6% | Mar 6, 2022 | Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. |
| CVE-2022-26505 | HIGH | 7.4 | 1.6% | Mar 6, 2022 | A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media file... |
| CVE-2022-26496 | CRITICAL | 9.8 | 3.5% | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the... |
| CVE-2022-26495 | CRITICAL | 9.8 | 2.7% | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0... |
| CVE-2022-26490 | HIGH | 7.8 | 0.4% | Mar 6, 2022 | st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTIO... |
| CVE-2022-26487 | — | — | — | Mar 6, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26143. Reason: This candidate is a reservation d... |
| CVE-2022-0845 | CRITICAL | 9.8 | 1.0% | Mar 5, 2022 | Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. |
| CVE-2022-24921 | HIGH | 7.5 | 3.2% | Mar 5, 2022 | regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. |
| CVE-2022-0849 | MEDIUM | 5.5 | 0.7% | Mar 5, 2022 | Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6. |
| CVE-2022-25465 | HIGH | 7.8 | 0.7% | Mar 5, 2022 | Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling. |
| CVE-2022-25044 | HIGH | 7.8 | 0.9% | Mar 5, 2022 | Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now