2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4429 | MEDIUM | 4.4 | 0.1% | Jan 10, 2023 | Avira Security for Windows contains an unquoted service path which allows attackers with local administrative privileges... |
| CVE-2022-4497 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2022-4491 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes befo... |
| CVE-2022-4479 | MEDIUM | 5.4 | 0.6% | Jan 9, 2023 | The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-4468 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before o... |
| CVE-2022-4426 | MEDIUM | 4.3 | 0.3% | Jan 9, 2023 | The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating setti... |
| CVE-2022-4394 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-4393 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its set... |
| CVE-2022-4392 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The iPanorama 360 WordPress Virtual Tour Builder plugin through 1.6.29 does not sanitise and escape some of its settings... |
| CVE-2022-4391 | MEDIUM | 5.4 | 0.5% | Jan 9, 2023 | The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could... |
| CVE-2022-4374 | MEDIUM | 6.1 | 0.6% | Jan 9, 2023 | The Bg Bible References WordPress plugin through 3.8.14 does not sanitize and escape a parameter before outputting it ba... |
| CVE-2022-4368 | MEDIUM | 6.1 | 0.3% | Jan 9, 2023 | The WP CSV WordPress plugin through 1.8.0.0 does not sanitize and escape a parameter before outputting it back in the pa... |
| CVE-2022-4325 | MEDIUM | 6.1 | 0.9% | Jan 9, 2023 | The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting ... |
| CVE-2022-4310 | MEDIUM | 6.1 | 0.6% | Jan 9, 2023 | The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which c... |
| CVE-2022-4301 | MEDIUM | 6.1 | 0.9% | Jan 9, 2023 | The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2022-4196 | MEDIUM | 4.8 | 0.5% | Jan 9, 2023 | The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allo... |
| CVE-2022-4103 | MEDIUM | 4.3 | 0.3% | Jan 9, 2023 | The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a te... |
| CVE-2022-46603 | MEDIUM | 6.1 | 0.5% | Jan 9, 2023 | An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file. |
| CVE-2022-3923 | MEDIUM | 4.3 | 0.5% | Jan 9, 2023 | The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its ... |
| CVE-2022-3855 | MEDIUM | 4.8 | 0.5% | Jan 9, 2023 | The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-4884 | MEDIUM | 4.9 | 0.5% | Jan 9, 2023 | Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files t... |
| CVE-2022-46258 | MEDIUM | 6.5 | 0.6% | Jan 9, 2023 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped tok... |
| CVE-2022-23509 | MEDIUM | 6 | 0.2% | Jan 9, 2023 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K... |
| CVE-2022-46769 | MEDIUM | 5.4 | 1.4% | Jan 9, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ... |
| CVE-2022-4882 | MEDIUM | 4.7 | 0.6% | Jan 9, 2023 | A vulnerability was found in kaltura mwEmbed up to 2.91. It has been rated as problematic. Affected by this issue is som... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now