2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4786MEDIUM5.4The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputt...
CVE-2022-4785MEDIUM5.4The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes bef...
CVE-2022-4784MEDIUM5.4The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4777MEDIUM5.4The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes be...
CVE-2022-4764MEDIUM5.4The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes ...
CVE-2022-4761MEDIUM5.4The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before...
CVE-2022-4754MEDIUM5.4The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attr...
CVE-2022-4752MEDIUM5.4The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4750MEDIUM5.4The WP Responsive Testimonials Slider And Widget WordPress plugin through 1.5 does not validate and escape some of its s...
CVE-2022-4714MEDIUM5.4The WP Dark Mode WordPress plugin before 4.0.0 does not validate and escape one of its shortcode attributes, which could...
CVE-2022-4669MEDIUM5.4The Page Builder: Live Composer WordPress plugin before 1.5.23 does not validate and escape some of its shortcode attrib...
CVE-2022-4666MEDIUM5.4The Markup (JSON-LD) structured in schema.org WordPress plugin through 4.8.1 does not validate and escape some of its sh...
CVE-2022-4622MEDIUM5.4The Login Logout Menu WordPress plugin through 1.3.3 does not validate and escape some of its shortcode attributes befor...
CVE-2022-4386MEDIUM4.3The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action...
CVE-2022-4385MEDIUM4.3The Intuitive Custom Post Order WordPress plugin before 3.1.4 does not check for authorization in the update-menu-order ...
CVE-2022-48340HIGH7.5In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
CVE-2022-48339HIGH7.8An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-iste...
CVE-2022-48338HIGH7.3An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local comm...
CVE-2022-48337CRITICAL9.8GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ...
CVE-2022-44216HIGH7.5Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without kno...
CVE-2022-3901MEDIUM6.1Prototype Pollution in Visioweb.js 1.10.6 allows attackers to execute XSS on the client system.
CVE-2022-48321LOW3.3Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to comm...
CVE-2022-48320MEDIUM4.3Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6...
CVE-2022-48319MEDIUM5.5Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and ...
CVE-2022-48318MEDIUM5.3No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which m...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now