2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-41680MEDIUM6.5Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln...
CVE-2022-41679MEDIUM6.1Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote att...
CVE-2022-3499MEDIUM6.5An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sce...
CVE-2022-44081MEDIUM5.5Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.
CVE-2022-44079MEDIUM5.5pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __san...
CVE-2022-43152MEDIUM5.5tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitS...
CVE-2022-43151MEDIUM5.5timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-quer...
CVE-2022-43148MEDIUM5.5rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h.
CVE-2022-3441MEDIUM4.8The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3440MEDIUM6.1The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attr...
CVE-2022-3420MEDIUM4.8The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, w...
CVE-2022-3419MEDIUM6.5The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo...
CVE-2022-3408MEDIUM4.8The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3237MEDIUM4.8The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege u...
CVE-2022-3096MEDIUM5.4The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's setti...
CVE-2022-2627MEDIUM6.1The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via...
CVE-2022-2190MEDIUM6.1The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2022-2167MEDIUM6.1The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via...
CVE-2022-40488MEDIUM6.5ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-40487MEDIUM6.1ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users ...
CVE-2022-3766MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-3765MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-40742MEDIUM6.5Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vul...
CVE-2022-40739MEDIUM5.4Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user priv...
CVE-2022-39027MEDIUM5.4U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user pri...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now