2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4667 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The RSS Aggregator by Feedzy WordPress plugin before 4.1.1 does not validate and escape some of its block options before... |
| CVE-2022-4654 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.3 does not validate and escape one of its shortcode attr... |
| CVE-2022-4651 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which ... |
| CVE-2022-4649 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which... |
| CVE-2022-4553 | MEDIUM | 4.3 | 0.3% | Jan 30, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow a... |
| CVE-2022-4552 | MEDIUM | 6.1 | 0.3% | Jan 30, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing saniti... |
| CVE-2022-4496 | MEDIUM | 6.1 | 0.6% | Jan 30, 2023 | The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 be... |
| CVE-2022-4472 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4470 | MEDIUM | 5.4 | 0.5% | Jan 30, 2023 | The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes... |
| CVE-2022-4306 | MEDIUM | 5.4 | 0.8% | Jan 30, 2023 | The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting ... |
| CVE-2022-46087 | MEDIUM | 5.4 | 0.6% | Jan 30, 2023 | CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin use... |
| CVE-2022-48303 | MEDIUM | 5.5 | 4.5% | Jan 30, 2023 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum... |
| CVE-2022-23552 | MEDIUM | 5.4 | 0.8% | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions ... |
| CVE-2022-4255 | MEDIUM | 5.3 | 0.5% | Jan 27, 2023 | An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6... |
| CVE-2022-4201 | MEDIUM | 5.3 | 0.5% | Jan 27, 2023 | A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all... |
| CVE-2022-46968 | MEDIUM | 5.4 | 0.5% | Jan 27, 2023 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attac... |
| CVE-2022-43980 | MEDIUM | 5.4 | 0.3% | Jan 27, 2023 | There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An a... |
| CVE-2022-39813 | MEDIUM | 6.1 | 0.5% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via ... |
| CVE-2022-39380 | MEDIUM | 5.3 | 0.6% | Jan 27, 2023 | Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptiona... |
| CVE-2022-48118 | MEDIUM | 6.1 | 0.5% | Jan 27, 2023 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter. |
| CVE-2022-4335 | MEDIUM | 4.3 | 0.8% | Jan 27, 2023 | A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 p... |
| CVE-2022-4285 | MEDIUM | 5.5 | 0.4% | Jan 27, 2023 | An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version i... |
| CVE-2022-48013 | MEDIUM | 5.4 | 0.5% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/i... |
| CVE-2022-48012 | MEDIUM | 6.1 | 1.4% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca... |
| CVE-2022-48010 | MEDIUM | 5.4 | 0.5% | Jan 27, 2023 | LimeSurvey v5.4.15 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /index.p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now