2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38146MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3).
CVE-2022-4096MEDIUM6.5Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.
CVE-2022-45017MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Overview Page settings module of WBCE CMS v1.5.4 allows attackers to e...
CVE-2022-45016MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ...
CVE-2022-45015MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ...
CVE-2022-45014MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ...
CVE-2022-45013MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to exe...
CVE-2022-45012MEDIUM4.8A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbi...
CVE-2022-3762MEDIUM6.5The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B...
CVE-2022-3753MEDIUM4.8The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-pri...
CVE-2022-3750MEDIUM4.7The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.
CVE-2022-3690MEDIUM4.8The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allo...
CVE-2022-3618MEDIUM4.8The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-priv...
CVE-2022-3336MEDIUM4.3The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attac...
CVE-2022-1581MEDIUM5.3The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO...
CVE-2022-0421MEDIUM6.1The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a...
CVE-2022-45146MEDIUM5.5An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collecto...
CVE-2022-4087MEDIUM4.3A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_...
CVE-2022-4069MEDIUM4.8Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-4068MEDIUM5.4A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Mo...
CVE-2022-4067MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-3562MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-3561MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-3516MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.
CVE-2022-4064MEDIUM6.3A vulnerability was found in Dalli up to 3.2.2. It has been classified as problematic. Affected is the function self.met...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now