2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4784 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4777 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-4764 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-4761 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4754 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attr... |
| CVE-2022-4752 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4750 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its s... |
| CVE-2022-4714 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4669 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attrib... |
| CVE-2022-4666 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its sh... |
| CVE-2022-4622 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes befor... |
| CVE-2022-4386 | MEDIUM | 4.3 | 0.3% | Feb 21, 2023 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action... |
| CVE-2022-4385 | MEDIUM | 4.3 | 0.5% | Feb 21, 2023 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ... |
| CVE-2022-3901 | MEDIUM | 6.1 | 0.4% | Feb 20, 2023 | Prototype Pollution in Visioweb.js 1.10.6 allows attackers to execute XSS on the client system. |
| CVE-2022-48320 | MEDIUM | 4.3 | 0.2% | Feb 20, 2023 | Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6... |
| CVE-2022-48319 | MEDIUM | 5.5 | 0.2% | Feb 20, 2023 | Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and ... |
| CVE-2022-48318 | MEDIUM | 5.3 | 0.5% | Feb 20, 2023 | No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which m... |
| CVE-2022-40348 | MEDIUM | 5.4 | 0.8% | Feb 18, 2023 | Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'em... |
| CVE-2022-48115 | MEDIUM | 6.1 | 0.4% | Feb 17, 2023 | The dropdown menu in jspreadsheet before v4.6.0 was discovered to be vulnerable to cross-site scripting (XSS). |
| CVE-2022-43579 | MEDIUM | 5.4 | 0.4% | Feb 17, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-... |
| CVE-2022-36775 | MEDIUM | 6.5 | 0.4% | Feb 17, 2023 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, 10.0.3.0, and10.0.4.0 is vulnerable to HTTP header injection, c... |
| CVE-2022-44299 | MEDIUM | 4.9 | 0.8% | Feb 16, 2023 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. |
| CVE-2022-0637 | MEDIUM | 6.1 | 0.4% | Feb 16, 2023 | open redirect in pollbot (pollbot.services.mozilla.com) in versions before 1.4.6 |
| CVE-2022-48327 | MEDIUM | 6.1 | 0.6% | Feb 16, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects t... |
| CVE-2022-48326 | MEDIUM | 6.1 | 0.6% | Feb 16, 2023 | Multiple Cross Site Scripting (XSS) vulnerabilities in Mapos 4.39.0 allow attackers to execute arbitrary code. Affects t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now