2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4745HIGH7.1The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod,...
CVE-2022-4682MEDIUM5.4The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before ...
CVE-2022-4678MEDIUM5.4The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes be...
CVE-2022-4656MEDIUM5.4The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortc...
CVE-2022-4628MEDIUM5.4The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attribut...
CVE-2022-4580MEDIUM5.4The Twenty20 Image Before-After WordPress plugin through 1.5.9 does not validate and escape some of its shortcode attrib...
CVE-2022-4562MEDIUM5.4The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes...
CVE-2022-4551MEDIUM5.4The Rich Table of Contents WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes b...
CVE-2022-4546HIGH7.2The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL sta...
CVE-2022-4512MEDIUM5.4The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes befo...
CVE-2022-4488MEDIUM5.4The Widgets on Pages WordPress plugin before 1.8.0 does not validate and escape its shortcode attributes before outputti...
CVE-2022-4473MEDIUM5.4The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before...
CVE-2022-4471MEDIUM5.4The YARPP WordPress plugin before 5.30.3 does not validate and escape some of its shortcode attributes before outputting...
CVE-2022-4458MEDIUM5.4The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes ...
CVE-2022-4448MEDIUM5.4The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputtin...
CVE-2022-4445CRITICAL9.8The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-40022CRITICAL9.8Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.
CVE-2022-3891MEDIUM5.3The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and...
CVE-2022-45725HIGH8.8Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute ar...
CVE-2022-45724MEDIUM5.4Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any...
CVE-2022-45455HIGH7.8Local privilege escalation due to incomplete uninstallation cleanup. The following products are affected: Acronis Cyber ...
CVE-2022-45454HIGH7.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent ...
CVE-2022-34397MEDIUM5.7 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 10.0.0.5 and below contains an ...
CVE-2022-48323CRITICAL9.8Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A...
CVE-2022-48322CRITICAL9.8NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affect...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now