2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4429MEDIUM4.4Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges...
CVE-2022-4497MEDIUM5.4The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputt...
CVE-2022-4491MEDIUM5.4The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes befo...
CVE-2022-4479MEDIUM5.4The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes be...
CVE-2022-4468MEDIUM5.4The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before o...
CVE-2022-4426MEDIUM4.3The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating setti...
CVE-2022-4394MEDIUM5.4The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could al...
CVE-2022-4393MEDIUM5.4The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its set...
CVE-2022-4392MEDIUM5.4The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings...
CVE-2022-4391MEDIUM5.4The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could...
CVE-2022-4374MEDIUM6.1The Bg Bible References WordPress plugin through 3.8.14 does not sanitize and escape a parameter before outputting it ba...
CVE-2022-4368MEDIUM6.1The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the pa...
CVE-2022-4325MEDIUM6.1The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting ...
CVE-2022-4310MEDIUM6.1The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which c...
CVE-2022-4301MEDIUM6.1The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it bac...
CVE-2022-4196MEDIUM4.8The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allo...
CVE-2022-4103MEDIUM4.3The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a te...
CVE-2022-46603MEDIUM6.1An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file.
CVE-2022-3923MEDIUM4.3The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its ...
CVE-2022-3855MEDIUM4.8The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-4884MEDIUM4.9Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files t...
CVE-2022-46258MEDIUM6.5An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped tok...
CVE-2022-23509MEDIUM6Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K...
CVE-2022-46769MEDIUM5.4An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ...
CVE-2022-4882MEDIUM4.7A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is som...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now