2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41980 | MEDIUM | 4.8 | 0.4% | Nov 8, 2022 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mantenimiento web plugin <= 0.13 on WordPress. |
| CVE-2022-40632 | MEDIUM | 5.4 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to to... |
| CVE-2022-40223 | MEDIUM | 4.3 | 0.4% | Nov 8, 2022 | Nonce token leakage and missing authorization in SearchWP premium plugin <= 4.2.5 on WordPress leading to plugin setting... |
| CVE-2022-40206 | MEDIUM | 4.3 | 0.5% | Nov 8, 2022 | Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers... |
| CVE-2022-40205 | MEDIUM | 4.3 | 0.5% | Nov 8, 2022 | Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers... |
| CVE-2022-40128 | MEDIUM | 6.5 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress le... |
| CVE-2022-32776 | MEDIUM | 4.8 | 0.4% | Nov 8, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Advanced Ads GmbH Advanced Ads – Ad Manager & AdSense ... |
| CVE-2022-32587 | MEDIUM | 4.3 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plug... |
| CVE-2022-30545 | MEDIUM | 4.8 | 0.4% | Nov 8, 2022 | Auth. Reflected Cross-Site Scripting (XSS) vulnerability in 5 Anker Connect plugin <= 1.2.6 on WordPress. |
| CVE-2022-27914 | MEDIUM | 6.1 | 0.5% | Nov 8, 2022 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads t... |
| CVE-2022-27855 | MEDIUM | 4.3 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress allows Plugin ... |
| CVE-2022-39069 | MEDIUM | 5.3 | 0.4% | Nov 8, 2022 | There is a SQL injection vulnerability in ZTE ZAIP-AIE. Due to lack of input verification by the server, an attacker cou... |
| CVE-2022-44321 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called... |
| CVE-2022-44320 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c ... |
| CVE-2022-44319 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c... |
| CVE-2022-44318 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c wh... |
| CVE-2022-44317 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c whe... |
| CVE-2022-44316 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when ... |
| CVE-2022-44315 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c wh... |
| CVE-2022-44314 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c w... |
| CVE-2022-44313 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in ... |
| CVE-2022-44312 | MEDIUM | 5.5 | 0.3% | Nov 8, 2022 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expressi... |
| CVE-2022-30694 | MEDIUM | 6.5 | 0.3% | Nov 8, 2022 | The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authen... |
| CVE-2022-36077 | MEDIUM | 6.1 | 0.5% | Nov 8, 2022 | The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions p... |
| CVE-2022-41434 | MEDIUM | 6.1 | 0.4% | Nov 8, 2022 | EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now