2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4475 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4474 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4467 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4443 | MEDIUM | 6.5 | 0.3% | Jan 23, 2023 | The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-4346 | MEDIUM | 5.3 | 0.7% | Jan 23, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used ... |
| CVE-2022-4307 | MEDIUM | 6.1 | 0.5% | Jan 23, 2023 | The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenti... |
| CVE-2022-41505 | MEDIUM | 6.4 | 0.4% | Jan 23, 2023 | An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by c... |
| CVE-2022-3811 | MEDIUM | 4.8 | 0.5% | Jan 23, 2023 | The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which ... |
| CVE-2022-46959 | MEDIUM | 4.3 | 0.8% | Jan 23, 2023 | An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal. |
| CVE-2022-48281 | MEDIUM | 5.5 | 0.5% | Jan 23, 2023 | processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of siz... |
| CVE-2022-47015 | MEDIUM | 6.5 | 1.5% | Jan 20, 2023 | MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbas... |
| CVE-2022-45558 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co... |
| CVE-2022-45557 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co... |
| CVE-2022-45542 | MEDIUM | 5.4 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing an... |
| CVE-2022-45541 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the v... |
| CVE-2022-45540 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value conta... |
| CVE-2022-45539 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new f... |
| CVE-2022-45538 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL". |
| CVE-2022-45537 | MEDIUM | 6.1 | 0.4% | Jan 20, 2023 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL". |
| CVE-2022-41733 | MEDIUM | 5.3 | 0.7% | Jan 20, 2023 | IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable unt... |
| CVE-2022-39193 | MEDIUM | 5.3 | 0.6% | Jan 20, 2023 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension ca... |
| CVE-2022-35977 | MEDIUM | 5.5 | 11.8% | Jan 20, 2023 | Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT... |
| CVE-2022-38110 | MEDIUM | 5.4 | 0.4% | Jan 20, 2023 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated r... |
| CVE-2022-43704 | MEDIUM | 5.9 | 1.9% | Jan 20, 2023 | The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requireme... |
| CVE-2022-43959 | MEDIUM | 4.9 | 1.0% | Jan 20, 2023 | Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remot... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now