2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0696MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
CVE-2022-0563MEDIUM5.5A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library use...
CVE-2022-25599MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress pl...
CVE-2022-24295HIGH8.8Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection v...
CVE-2022-23984HIGH7.5Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
CVE-2022-23983HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protecti...
CVE-2022-22308HIGH7.8IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file inc...
CVE-2022-0708MEDIUM6.5Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allo...
CVE-2022-0564MEDIUM5.3A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An...
CVE-2022-0692MEDIUM6.1Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
CVE-2022-24553CRITICAL9.8An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resul...
CVE-2022-0313MEDIUM4.3The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow att...
CVE-2022-0288MEDIUM6.1The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escap...
CVE-2022-0279LOW3.1The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, whi...
CVE-2022-0255HIGH7.2The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter befor...
CVE-2022-0252MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute i...
CVE-2022-0234MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the wooc...
CVE-2022-0228HIGH7.2The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters b...
CVE-2022-0211MEDIUM4.8The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv...
CVE-2022-0199MEDIUM4.3The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail...
CVE-2022-0186MEDIUM5.4The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description fiel...
CVE-2022-0164MEDIUM4.3The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its co...
CVE-2022-0134HIGH8.8The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features,...
CVE-2022-0691CRITICAL9.8Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVE-2022-25297HIGH8.8This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names during upload using Http...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now