2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38146 | MEDIUM | 5.4 | 0.5% | Nov 21, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). |
| CVE-2022-4096 | MEDIUM | 6.5 | 1.4% | Nov 21, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2. |
| CVE-2022-45017 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to e... |
| CVE-2022-45016 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ... |
| CVE-2022-45015 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ... |
| CVE-2022-45014 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ... |
| CVE-2022-45013 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to exe... |
| CVE-2022-45012 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbi... |
| CVE-2022-3762 | MEDIUM | 6.5 | 0.9% | Nov 21, 2022 | The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B... |
| CVE-2022-3753 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-pri... |
| CVE-2022-3750 | MEDIUM | 4.7 | 0.4% | Nov 21, 2022 | The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. |
| CVE-2022-3690 | MEDIUM | 4.8 | 0.6% | Nov 21, 2022 | The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allo... |
| CVE-2022-3618 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-priv... |
| CVE-2022-3336 | MEDIUM | 4.3 | 0.3% | Nov 21, 2022 | The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attac... |
| CVE-2022-1581 | MEDIUM | 5.3 | 0.6% | Nov 21, 2022 | The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO... |
| CVE-2022-0421 | MEDIUM | 6.1 | 0.5% | Nov 21, 2022 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a... |
| CVE-2022-45146 | MEDIUM | 5.5 | 0.4% | Nov 21, 2022 | An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collecto... |
| CVE-2022-4087 | MEDIUM | 4.3 | 0.5% | Nov 21, 2022 | A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_... |
| CVE-2022-4069 | MEDIUM | 4.8 | 93.3% | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. |
| CVE-2022-4068 | MEDIUM | 5.4 | 34.0% | Nov 20, 2022 | A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Mo... |
| CVE-2022-4067 | MEDIUM | 5.4 | 93.7% | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
| CVE-2022-3562 | MEDIUM | 5.4 | 94.2% | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
| CVE-2022-3561 | MEDIUM | 6.1 | 0.5% | Nov 20, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0. |
| CVE-2022-3516 | MEDIUM | 6.1 | 0.5% | Nov 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0. |
| CVE-2022-4064 | MEDIUM | 6.3 | 1.3% | Nov 19, 2022 | A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.met... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now