2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4164MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4163MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4162MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4161MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4160MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4159MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4157MEDIUM4.9The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4155MEDIUM4.9The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4154MEDIUM4.9The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating...
CVE-2022-4153MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4152MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the...
CVE-2022-4151MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4150MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4110MEDIUM4.8The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-4042MEDIUM4.8The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its set...
CVE-2022-3840MEDIUM4.8The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could a...
CVE-2022-3835MEDIUM4.8The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-41767MEDIUM5.3An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When chan...
CVE-2022-41765MEDIUM5.3An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserT...
CVE-2022-24120MEDIUM4.6Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iN...
CVE-2022-37310MEDIUM6.1OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#...
CVE-2022-37309MEDIUM6.1OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
CVE-2022-29853MEDIUM5.4OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HT...
CVE-2022-29852MEDIUM5.4OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
CVE-2022-37308MEDIUM6.1OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now