2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4164 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4163 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4162 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4161 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4160 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4159 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4157 | MEDIUM | 4.9 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4155 | MEDIUM | 4.9 | 0.8% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4154 | MEDIUM | 4.9 | 0.9% | Dec 26, 2022 | The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating... |
| CVE-2022-4153 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4152 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the... |
| CVE-2022-4151 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4150 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4110 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2022-4042 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its set... |
| CVE-2022-3840 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could a... |
| CVE-2022-3835 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2022-41767 | MEDIUM | 5.3 | 0.6% | Dec 26, 2022 | An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When chan... |
| CVE-2022-41765 | MEDIUM | 5.3 | 0.6% | Dec 26, 2022 | An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserT... |
| CVE-2022-24120 | MEDIUM | 4.6 | 0.2% | Dec 26, 2022 | Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iN... |
| CVE-2022-37310 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#... |
| CVE-2022-37309 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. |
| CVE-2022-29853 | MEDIUM | 5.4 | 0.4% | Dec 26, 2022 | OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HT... |
| CVE-2022-29852 | MEDIUM | 5.4 | 0.4% | Dec 26, 2022 | OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked. |
| CVE-2022-37308 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now