2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4786 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2022-4785 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-4784 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4777 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-4764 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-4761 | MEDIUM | 5.4 | 0.6% | Feb 21, 2023 | The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4754 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attr... |
| CVE-2022-4752 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4750 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its s... |
| CVE-2022-4714 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4669 | MEDIUM | 5.4 | 0.4% | Feb 21, 2023 | The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attrib... |
| CVE-2022-4666 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its sh... |
| CVE-2022-4622 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes befor... |
| CVE-2022-4386 | MEDIUM | 4.3 | 0.3% | Feb 21, 2023 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action... |
| CVE-2022-4385 | MEDIUM | 4.3 | 0.5% | Feb 21, 2023 | The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ... |
| CVE-2022-48340 | HIGH | 7.5 | 0.9% | Feb 21, 2023 | In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free. |
| CVE-2022-48339 | HIGH | 7.8 | 1.1% | Feb 20, 2023 | An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-iste... |
| CVE-2022-48338 | HIGH | 7.3 | 1.6% | Feb 20, 2023 | An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local comm... |
| CVE-2022-48337 | CRITICAL | 9.8 | 1.6% | Feb 20, 2023 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ... |
| CVE-2022-44216 | HIGH | 7.5 | 0.7% | Feb 20, 2023 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without kno... |
| CVE-2022-3901 | MEDIUM | 6.1 | 0.4% | Feb 20, 2023 | Prototype Pollution in Visioweb.js 1.10.6 allows attackers to execute XSS on the client system. |
| CVE-2022-48321 | LOW | 3.3 | 0.3% | Feb 20, 2023 | Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to comm... |
| CVE-2022-48320 | MEDIUM | 4.3 | 0.2% | Feb 20, 2023 | Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6... |
| CVE-2022-48319 | MEDIUM | 5.5 | 0.2% | Feb 20, 2023 | Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and ... |
| CVE-2022-48318 | MEDIUM | 5.3 | 0.5% | Feb 20, 2023 | No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which m... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now