2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24189 | MEDIUM | 6.5 | 0.5% | Nov 28, 2022 | The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. R... |
| CVE-2022-46147 | MEDIUM | 6.1 | 0.8% | Nov 28, 2022 | Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target... |
| CVE-2022-44937 | MEDIUM | 6.5 | 0.3% | Nov 28, 2022 | Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrato... |
| CVE-2022-41965 | MEDIUM | 6.1 | 0.3% | Nov 28, 2022 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open... |
| CVE-2022-4104 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compressio... |
| CVE-2022-4169 | MEDIUM | 5.3 | 0.7% | Nov 28, 2022 | The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.... |
| CVE-2022-41732 | MEDIUM | 5.5 | 0.2% | Nov 28, 2022 | IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Forc... |
| CVE-2022-44284 | MEDIUM | 5.4 | 0.5% | Nov 28, 2022 | Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-41944 | MEDIUM | 4.3 | 0.4% | Nov 28, 2022 | Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr... |
| CVE-2022-41921 | MEDIUM | 4.3 | 0.5% | Nov 28, 2022 | Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim... |
| CVE-2022-3850 | MEDIUM | 4.3 | 0.3% | Nov 28, 2022 | The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow a... |
| CVE-2022-3847 | MEDIUM | 6.1 | 0.3% | Nov 28, 2022 | The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is mi... |
| CVE-2022-3839 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-3834 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-3833 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, wh... |
| CVE-2022-3831 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2022-3828 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2022-3824 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could ... |
| CVE-2022-3823 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, whi... |
| CVE-2022-3822 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-3610 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which coul... |
| CVE-2022-3601 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could... |
| CVE-2022-3511 | MEDIUM | 6.5 | 0.7% | Nov 28, 2022 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded bel... |
| CVE-2022-2983 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users ... |
| CVE-2022-2311 | MEDIUM | 6.1 | 0.5% | Nov 28, 2022 | The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now