2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3614 | MEDIUM | 6.1 | 0.4% | Jan 3, 2023 | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa... |
| CVE-2022-4025 | MEDIUM | 4.3 | 0.5% | Jan 2, 2023 | Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-ori... |
| CVE-2022-3863 | MEDIUM | 6.1 | 0.4% | Jan 2, 2023 | Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo... |
| CVE-2022-0801 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X... |
| CVE-2022-0337 | MEDIUM | 6.5 | 1.3% | Jan 2, 2023 | Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac... |
| CVE-2022-4417 | MEDIUM | 5.3 | 0.7% | Jan 2, 2023 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the RES... |
| CVE-2022-4381 | MEDIUM | 5.4 | 0.5% | Jan 2, 2023 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4369 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting ... |
| CVE-2022-4362 | MEDIUM | 5.4 | 0.6% | Jan 2, 2023 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4340 | MEDIUM | 5.3 | 0.7% | Jan 2, 2023 | The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in... |
| CVE-2022-4329 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before out... |
| CVE-2022-4260 | MEDIUM | 4.8 | 0.9% | Jan 2, 2023 | The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2022-4256 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The All-in-One Addons for Elementor WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, whi... |
| CVE-2022-4236 | MEDIUM | 6.5 | 0.8% | Jan 2, 2023 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ... |
| CVE-2022-4200 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could all... |
| CVE-2022-4198 | MEDIUM | 4.8 | 0.6% | Jan 2, 2023 | The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2022-4142 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg... |
| CVE-2022-4119 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, wh... |
| CVE-2022-4114 | MEDIUM | 5.4 | 0.5% | Jan 2, 2023 | The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as ... |
| CVE-2022-4057 | MEDIUM | 5.3 | 1.5% | Jan 2, 2023 | The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs... |
| CVE-2022-3994 | MEDIUM | 4.3 | 0.8% | Jan 2, 2023 | The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, w... |
| CVE-2022-3936 | MEDIUM | 4.8 | 0.5% | Jan 2, 2023 | The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow hig... |
| CVE-2022-48197 | MEDIUM | 6.1 | 6.6% | Jan 2, 2023 | Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree... |
| CVE-2022-45213 | MEDIUM | 5.3 | 0.6% | Jan 1, 2023 | perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL. |
| CVE-2022-45027 | MEDIUM | 5.3 | 0.6% | Jan 1, 2023 | perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determin... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now