2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26156MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious pay...
CVE-2022-26155MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload ...
CVE-2022-24712HIGH8.8CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1....
CVE-2022-24711CRITICAL9.8CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input...
CVE-2022-25642MEDIUM6.1Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.
CVE-2022-24685HIGH7.5HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may ...
CVE-2022-24572MEDIUM6.1Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Usernam...
CVE-2022-24571CRITICAL9.8Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL...
CVE-2022-0768CRITICAL9.1Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
CVE-2022-23988MEDIUM6.1The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unaut...
CVE-2022-23987MEDIUM4.8The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow ...
CVE-2022-23912MEDIUM6.1The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp...
CVE-2022-23911HIGH7.2The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before usin...
CVE-2022-0412CRITICAL9.8The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d...
CVE-2022-0411HIGH8.8The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a ...
CVE-2022-0385MEDIUM6.1The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe...
CVE-2022-0383HIGH7.2The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter ...
CVE-2022-0377MEDIUM4.3Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. A...
CVE-2022-0360MEDIUM4.8The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped...
CVE-2022-0345MEDIUM4.3The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it...
CVE-2022-0328MEDIUM4.7The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could ...
CVE-2022-0189MEDIUM6.1The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_item...
CVE-2022-0150MEDIUM6.1The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before...
CVE-2022-26159MEDIUM5.3The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as...
CVE-2022-0772MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now