2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4667MEDIUM5.4The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before...
CVE-2022-4654MEDIUM5.4The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attr...
CVE-2022-4651MEDIUM5.4The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which ...
CVE-2022-4649MEDIUM5.4The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which...
CVE-2022-4553MEDIUM4.3The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow a...
CVE-2022-4552MEDIUM6.1The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing saniti...
CVE-2022-4496MEDIUM6.1The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 be...
CVE-2022-4472MEDIUM5.4The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4470MEDIUM5.4The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes...
CVE-2022-4306MEDIUM5.4The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting ...
CVE-2022-46087MEDIUM5.4CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin use...
CVE-2022-48303MEDIUM5.5GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum...
CVE-2022-23552MEDIUM5.4Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions ...
CVE-2022-4255MEDIUM5.3An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6...
CVE-2022-4201MEDIUM5.3A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all...
CVE-2022-46968MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attac...
CVE-2022-43980MEDIUM5.4There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An a...
CVE-2022-39813MEDIUM6.1Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via ...
CVE-2022-39380MEDIUM5.3Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptiona...
CVE-2022-48118MEDIUM6.1Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
CVE-2022-4335MEDIUM4.3A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 p...
CVE-2022-4285MEDIUM5.5An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version i...
CVE-2022-48013MEDIUM5.4Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/i...
CVE-2022-48012MEDIUM6.1Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca...
CVE-2022-48010MEDIUM5.4LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now