2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35693MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-30679MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-40435MEDIUM4.8Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerabil...
CVE-2022-47512MEDIUM5.5Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo...
CVE-2022-31683MEDIUM5.4Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can s...
CVE-2022-4613MEDIUM6.5A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr...
CVE-2022-4612MEDIUM6.5A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified ...
CVE-2022-4611MEDIUM5.3A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser...
CVE-2022-4610MEDIUM5.5A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br...
CVE-2022-4125MEDIUM4.3The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popup...
CVE-2022-4124MEDIUM4.3The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which...
CVE-2022-4112MEDIUM4.8The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-4108MEDIUM4.9The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system ...
CVE-2022-4107MEDIUM6.5The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as w...
CVE-2022-4058MEDIUM5.4The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting ...
CVE-2022-4024MEDIUM6.5The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an i...
CVE-2022-3987MEDIUM5.4The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3986MEDIUM5.4The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes be...
CVE-2022-3985MEDIUM5.4The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3984MEDIUM5.4The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes ...
CVE-2022-3983MEDIUM5.4The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3961MEDIUM6.5The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessi...
CVE-2022-3937MEDIUM5.4The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow u...
CVE-2022-3832MEDIUM4.8The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-4609MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now