2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41695MEDIUM6.5Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5...
CVE-2022-41619MEDIUM6.5Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.
CVE-2022-40702MEDIUM4.3Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pic...
CVE-2022-40203HIGH8.8Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dy...
CVE-2022-38141MEDIUM6.5Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email fo...
CVE-2022-36418CRITICAL9.8Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a...
CVE-2022-31021MEDIUM5.3Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is ...
CVE-2022-3899HIGH8.1The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File M...
CVE-2022-3836MEDIUM4.8The Seed Social WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-3829MEDIUM4.8The Font Awesome 4 Menus WordPress plugin through 4.7.0 does not sanitise and escape some of its settings, which could a...
CVE-2022-3764HIGH7.2The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.
CVE-2022-3739MEDIUM5.4The WP Best Quiz WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with...
CVE-2022-3604HIGH7.8The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could...
CVE-2022-3194MEDIUM5.4The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allo...
CVE-2022-2413MEDIUM5.4The Slide Anything WordPress plugin before 2.3.47 does not properly sanitize or escape the slide title before outputting...
CVE-2022-23180MEDIUM4.3The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks...
CVE-2022-23179MEDIUM4.8The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields bef...
CVE-2022-1760MEDIUM4.3The Core Control WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which coul...
CVE-2022-1618MEDIUM6.1The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lackin...
CVE-2022-1617MEDIUM6.1The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacki...
CVE-2022-1609CRITICAL9.8The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking co...
CVE-2022-1563MEDIUM5.3The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a s...
CVE-2022-1538HIGH7.2Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such ...
CVE-2022-0775MEDIUM4.3The WooCommerce WordPress plugin before 6.2.1 does not have proper authorisation check when deleting reviews, which coul...
CVE-2022-0402MEDIUM6.1The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zost...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now