2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26156 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious pay... |
| CVE-2022-26155 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload ... |
| CVE-2022-24712 | HIGH | 8.8 | 0.5% | Feb 28, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.... |
| CVE-2022-24711 | CRITICAL | 9.8 | 1.1% | Feb 28, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input... |
| CVE-2022-25642 | MEDIUM | 6.1 | 1.4% | Feb 28, 2022 | Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution. |
| CVE-2022-24685 | HIGH | 7.5 | 1.5% | Feb 28, 2022 | HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may ... |
| CVE-2022-24572 | MEDIUM | 6.1 | 0.6% | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Usernam... |
| CVE-2022-24571 | CRITICAL | 9.8 | 1.6% | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL... |
| CVE-2022-0768 | CRITICAL | 9.1 | 1.6% | Feb 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. |
| CVE-2022-23988 | MEDIUM | 6.1 | 2.2% | Feb 28, 2022 | The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unaut... |
| CVE-2022-23987 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow ... |
| CVE-2022-23912 | MEDIUM | 6.1 | 0.9% | Feb 28, 2022 | The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp... |
| CVE-2022-23911 | HIGH | 7.2 | 1.4% | Feb 28, 2022 | The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before usin... |
| CVE-2022-0412 | CRITICAL | 9.8 | 74.6% | Feb 28, 2022 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d... |
| CVE-2022-0411 | HIGH | 8.8 | 1.5% | Feb 28, 2022 | The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a ... |
| CVE-2022-0385 | MEDIUM | 6.1 | 1.4% | Feb 28, 2022 | The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe... |
| CVE-2022-0383 | HIGH | 7.2 | 1.4% | Feb 28, 2022 | The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter ... |
| CVE-2022-0377 | MEDIUM | 4.3 | 3.2% | Feb 28, 2022 | Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. A... |
| CVE-2022-0360 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped... |
| CVE-2022-0345 | MEDIUM | 4.3 | 0.4% | Feb 28, 2022 | The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it... |
| CVE-2022-0328 | MEDIUM | 4.7 | 0.5% | Feb 28, 2022 | The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could ... |
| CVE-2022-0189 | MEDIUM | 6.1 | 2.2% | Feb 28, 2022 | The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_item... |
| CVE-2022-0150 | MEDIUM | 6.1 | 1.7% | Feb 28, 2022 | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before... |
| CVE-2022-26159 | MEDIUM | 5.3 | 13.4% | Feb 28, 2022 | The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as... |
| CVE-2022-0772 | MEDIUM | 4.8 | 0.6% | Feb 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now