2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24189MEDIUM6.5The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. R...
CVE-2022-46147MEDIUM6.1Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target...
CVE-2022-44937MEDIUM6.5Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrato...
CVE-2022-41965MEDIUM6.1Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open...
CVE-2022-4104MEDIUM5.5A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compressio...
CVE-2022-4169MEDIUM5.3The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3....
CVE-2022-41732MEDIUM5.5 IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Forc...
CVE-2022-44284MEDIUM5.4Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).
CVE-2022-41944MEDIUM4.3Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr...
CVE-2022-41921MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim...
CVE-2022-3850MEDIUM4.3The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow a...
CVE-2022-3847MEDIUM6.1The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is mi...
CVE-2022-3839MEDIUM4.8The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow...
CVE-2022-3834MEDIUM4.8The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-3833MEDIUM4.8The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, wh...
CVE-2022-3831MEDIUM4.8The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-3828MEDIUM4.8The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allo...
CVE-2022-3824MEDIUM4.8The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could ...
CVE-2022-3823MEDIUM4.8The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, whi...
CVE-2022-3822MEDIUM4.8The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could al...
CVE-2022-3610MEDIUM4.8The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which coul...
CVE-2022-3601MEDIUM4.8The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could...
CVE-2022-3511MEDIUM6.5The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded bel...
CVE-2022-2983MEDIUM4.8The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users ...
CVE-2022-2311MEDIUM6.1The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now