2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-3614MEDIUM6.1In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa...
CVE-2022-4025MEDIUM4.3Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-ori...
CVE-2022-3863MEDIUM6.1Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo...
CVE-2022-0801MEDIUM6.1Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X...
CVE-2022-0337MEDIUM6.5Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac...
CVE-2022-4417MEDIUM5.3The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the RES...
CVE-2022-4381MEDIUM5.4The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could...
CVE-2022-4369MEDIUM6.1The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting ...
CVE-2022-4362MEDIUM5.4The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could...
CVE-2022-4340MEDIUM5.3The BookingPress WordPress plugin before 1.0.31 suffers from an Insecure Direct Object Reference (IDOR) vulnerability in...
CVE-2022-4329MEDIUM6.1The Product list Widget for Woocommerce WordPress plugin through 1.0 does not sanitise and escape a parameter before out...
CVE-2022-4260MEDIUM4.8The WP-Ban WordPress plugin before 1.69.1 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-4256MEDIUM4.8The All-in-One Addons for Elementor WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, whi...
CVE-2022-4236MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content ...
CVE-2022-4200MEDIUM4.8The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could all...
CVE-2022-4198MEDIUM4.8The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-4142MEDIUM4.8The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg...
CVE-2022-4119MEDIUM4.8The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, wh...
CVE-2022-4114MEDIUM5.4The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as ...
CVE-2022-4057MEDIUM5.3The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs...
CVE-2022-3994MEDIUM4.3The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, w...
CVE-2022-3936MEDIUM4.8The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow hig...
CVE-2022-48197MEDIUM6.1Reflected cross-site scripting (XSS) exists in Sandbox examples in the YUI2 repository. The download distributions, Tree...
CVE-2022-45213MEDIUM5.3perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
CVE-2022-45027MEDIUM5.3perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now