2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41680 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln... |
| CVE-2022-41679 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote att... |
| CVE-2022-3499 | MEDIUM | 6.5 | 0.8% | Oct 31, 2022 | An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sce... |
| CVE-2022-44081 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail. |
| CVE-2022-44079 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __san... |
| CVE-2022-43152 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitS... |
| CVE-2022-43151 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-quer... |
| CVE-2022-43148 | MEDIUM | 5.5 | 0.3% | Oct 31, 2022 | rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h. |
| CVE-2022-3441 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-3440 | MEDIUM | 6.1 | 0.5% | Oct 31, 2022 | The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attr... |
| CVE-2022-3420 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, w... |
| CVE-2022-3419 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo... |
| CVE-2022-3408 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-3237 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege u... |
| CVE-2022-3096 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's setti... |
| CVE-2022-2627 | MEDIUM | 6.1 | 1.0% | Oct 31, 2022 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via... |
| CVE-2022-2190 | MEDIUM | 6.1 | 0.6% | Oct 31, 2022 | The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outp... |
| CVE-2022-2167 | MEDIUM | 6.1 | 0.6% | Oct 31, 2022 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via... |
| CVE-2022-40488 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). |
| CVE-2022-40487 | MEDIUM | 6.1 | 0.4% | Oct 31, 2022 | ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users ... |
| CVE-2022-3766 | MEDIUM | 6.1 | 5.7% | Oct 31, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-3765 | MEDIUM | 5.4 | 0.5% | Oct 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-40742 | MEDIUM | 6.5 | 0.6% | Oct 31, 2022 | Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vul... |
| CVE-2022-40739 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user priv... |
| CVE-2022-39027 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user pri... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now