2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35693 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-30679 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-40435 | MEDIUM | 4.8 | 0.6% | Dec 19, 2022 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerabil... |
| CVE-2022-47512 | MEDIUM | 5.5 | 0.2% | Dec 19, 2022 | Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Clo... |
| CVE-2022-31683 | MEDIUM | 5.4 | 0.4% | Dec 19, 2022 | Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) contains an authorization bypass issue. A Concourse user can s... |
| CVE-2022-4613 | MEDIUM | 6.5 | 0.7% | Dec 19, 2022 | A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as cr... |
| CVE-2022-4612 | MEDIUM | 6.5 | 0.9% | Dec 19, 2022 | A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified ... |
| CVE-2022-4611 | MEDIUM | 5.3 | 1.2% | Dec 19, 2022 | A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser... |
| CVE-2022-4610 | MEDIUM | 5.5 | 0.2% | Dec 19, 2022 | A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Br... |
| CVE-2022-4125 | MEDIUM | 4.3 | 0.3% | Dec 19, 2022 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popup... |
| CVE-2022-4124 | MEDIUM | 4.3 | 0.3% | Dec 19, 2022 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which... |
| CVE-2022-4112 | MEDIUM | 4.8 | 0.5% | Dec 19, 2022 | The Quizlord WordPress plugin through 2.0 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2022-4108 | MEDIUM | 4.9 | 0.8% | Dec 19, 2022 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system ... |
| CVE-2022-4107 | MEDIUM | 6.5 | 0.4% | Dec 19, 2022 | The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as w... |
| CVE-2022-4058 | MEDIUM | 5.4 | 0.2% | Dec 19, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting ... |
| CVE-2022-4024 | MEDIUM | 6.5 | 0.3% | Dec 19, 2022 | The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an i... |
| CVE-2022-3987 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3986 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-3985 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3984 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-3983 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3961 | MEDIUM | 6.5 | 0.7% | Dec 19, 2022 | The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessi... |
| CVE-2022-3937 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow u... |
| CVE-2022-3832 | MEDIUM | 4.8 | 0.5% | Dec 19, 2022 | The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-4609 | MEDIUM | 5.4 | 0.7% | Dec 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now