2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4475MEDIUM5.4The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4474MEDIUM5.4The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4467MEDIUM5.4The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4443MEDIUM6.5The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-4346MEDIUM5.3The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used ...
CVE-2022-4307MEDIUM6.1The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenti...
CVE-2022-41505MEDIUM6.4An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by c...
CVE-2022-3811MEDIUM4.8The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which ...
CVE-2022-46959MEDIUM4.3An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal.
CVE-2022-48281MEDIUM5.5processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of siz...
CVE-2022-47015MEDIUM6.5MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbas...
CVE-2022-45558MEDIUM6.1Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co...
CVE-2022-45557MEDIUM6.1Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co...
CVE-2022-45542MEDIUM5.4EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing an...
CVE-2022-45541MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the v...
CVE-2022-45540MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value conta...
CVE-2022-45539MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new f...
CVE-2022-45538MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
CVE-2022-45537MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
CVE-2022-41733MEDIUM5.3 IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable unt...
CVE-2022-39193MEDIUM5.3An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension ca...
CVE-2022-35977MEDIUM5.5Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT...
CVE-2022-38110MEDIUM5.4In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated r...
CVE-2022-43704MEDIUM5.9The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requireme...
CVE-2022-43959MEDIUM4.9Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remot...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now