2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24110MEDIUM6.5Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later...
CVE-2022-0576MEDIUM6.1Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
CVE-2022-0575MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-0572HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0571MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
CVE-2022-0570CRITICAL9.8Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-0569MEDIUM4.3Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
CVE-2022-0565MEDIUM6.4Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0214HIGH7.5The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be ...
CVE-2022-0212MEDIUM6.1The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting...
CVE-2022-0208MEDIUM6.1The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting ...
CVE-2022-0206MEDIUM6.1The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back...
CVE-2022-0201MEDIUM6.1The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do no...
CVE-2022-0200MEDIUM5.4Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outp...
CVE-2022-0193MEDIUM6.1The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in...
CVE-2022-0190HIGH8.8The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter o...
CVE-2022-0188MEDIUM5.3The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l...
CVE-2022-0176MEDIUM6.1The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter bef...
CVE-2022-22765HIGH7.8BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to a...
CVE-2022-0311HIGH8.8Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a us...
CVE-2022-0310HIGH8.8Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exp...
CVE-2022-0309MEDIUM6.5Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navi...
CVE-2022-0308HIGH8.8Use after free in Data Transfer in Google Chrome on Chrome OS prior to 97.0.4692.99 allowed a remote attacker who convin...
CVE-2022-0307HIGH8.8Use after free in Optimization Guide in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a us...
CVE-2022-0306HIGH8.8Heap buffer overflow in PDFium in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially exploit h...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now