2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32517MEDIUM6.5A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to t...
CVE-2022-32516MEDIUM6.5A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and ...
CVE-2022-40137MEDIUM6.7A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated priv...
CVE-2022-40136MEDIUM4.4An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may ...
CVE-2022-40135MEDIUM4.4An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker wi...
CVE-2022-40134MEDIUM4.4An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker w...
CVE-2022-34888MEDIUM4.3The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal service...
CVE-2022-34885MEDIUM6.7An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permis...
CVE-2022-34884MEDIUM6.5A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to caus...
CVE-2022-4872MEDIUM4.3The Chained Products WordPress plugin before 2.12.0 does not have authorisation and CSRF checks, as well as does not ens...
CVE-2022-4837MEDIUM5.4The CPO Companion WordPress plugin before 1.1.0 does not validate and escape some of its shortcode attributes before out...
CVE-2022-4835MEDIUM5.4The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes be...
CVE-2022-4834MEDIUM5.4The CPT Bootstrap Carousel WordPress plugin through 1.12 does not validate and escape some of its shortcode attributes b...
CVE-2022-4831MEDIUM5.4The Custom User Profile Fields for User Registration WordPress plugin before 1.8.1 does not validate and escape some of ...
CVE-2022-4828MEDIUM5.4The Bold Timeline Lite WordPress plugin before 1.1.5 does not validate and escape some of its shortcode attributes befor...
CVE-2022-4793MEDIUM5.4The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which coul...
CVE-2022-4792MEDIUM5.4The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, ...
CVE-2022-4787MEDIUM5.4Themify Shortcodes WordPress plugin before 2.0.8 does not validate and escape one of its shortcode attributes, which cou...
CVE-2022-4781MEDIUM5.4The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, wh...
CVE-2022-4776MEDIUM5.4The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before out...
CVE-2022-4765MEDIUM5.4The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes ...
CVE-2022-4763MEDIUM5.4The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outpu...
CVE-2022-4749MEDIUM5.4The Posts List Designer by Category WordPress plugin before 3.2 does not validate and escape some of its shortcode attri...
CVE-2022-4699MEDIUM5.4The MediaElement.js WordPress plugin through 4.2.8 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4671MEDIUM5.4The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputti...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now