2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4745 | HIGH | 7.1 | 0.3% | Feb 13, 2023 | The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod,... |
| CVE-2022-4682 | MEDIUM | 5.4 | 0.7% | Feb 13, 2023 | The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4678 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-4656 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortc... |
| CVE-2022-4628 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attribut... |
| CVE-2022-4580 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The Twenty20 Image Before-After WordPress plugin through 1.5.9 does not validate and escape some of its shortcode attrib... |
| CVE-2022-4562 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes... |
| CVE-2022-4551 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes b... |
| CVE-2022-4546 | HIGH | 7.2 | 1.0% | Feb 13, 2023 | The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL sta... |
| CVE-2022-4512 | MEDIUM | 5.4 | 0.8% | Feb 13, 2023 | The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes befo... |
| CVE-2022-4488 | MEDIUM | 5.4 | 0.7% | Feb 13, 2023 | The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputti... |
| CVE-2022-4473 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4471 | MEDIUM | 5.4 | 0.7% | Feb 13, 2023 | The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting... |
| CVE-2022-4458 | MEDIUM | 5.4 | 0.5% | Feb 13, 2023 | The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-4448 | MEDIUM | 5.4 | 0.6% | Feb 13, 2023 | The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputtin... |
| CVE-2022-4445 | CRITICAL | 9.8 | 1.1% | Feb 13, 2023 | The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-40022 | CRITICAL | 9.8 | 92.5% | Feb 13, 2023 | Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. |
| CVE-2022-3891 | MEDIUM | 5.3 | 0.7% | Feb 13, 2023 | The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and... |
| CVE-2022-45725 | HIGH | 8.8 | 8.8% | Feb 13, 2023 | Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute ar... |
| CVE-2022-45724 | MEDIUM | 5.4 | 0.7% | Feb 13, 2023 | Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any... |
| CVE-2022-45455 | HIGH | 7.8 | 0.1% | Feb 13, 2023 | Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber ... |
| CVE-2022-45454 | HIGH | 7.5 | 0.3% | Feb 13, 2023 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent ... |
| CVE-2022-34397 | MEDIUM | 5.7 | 0.2% | Feb 13, 2023 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an ... |
| CVE-2022-48323 | CRITICAL | 9.8 | 56.8% | Feb 13, 2023 | Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A... |
| CVE-2022-48322 | CRITICAL | 9.8 | 0.7% | Feb 13, 2023 | NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affect... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now