2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-3025MEDIUM5.4The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allow...
CVE-2022-3024MEDIUM5.4The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, al...
CVE-2022-2926MEDIUM4.9The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privil...
CVE-2022-2405MEDIUM4.3The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowin...
CVE-2022-2404MEDIUM6.1The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-1755MEDIUM5.4The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with ...
CVE-2022-1613MEDIUM5.3The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers ov...
CVE-2022-38970MEDIUM6.5ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs ...
CVE-2022-38553MEDIUM6.1Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulner...
CVE-2022-21169MEDIUM6.1The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allo...
CVE-2022-23461MEDIUM6.1Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vul...
CVE-2022-39242MEDIUM5.3Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the...
CVE-2022-39240MEDIUM5.4MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading...
CVE-2022-3278MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
CVE-2022-40132MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to...
CVE-2022-40103MEDIUM5.5Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability...
CVE-2022-38704MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 40...
CVE-2022-38439MEDIUM5.4Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2022-38438MEDIUM5.4Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2022-36340MEDIUM5.3Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress.
CVE-2022-35251MEDIUM5.4A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an ad...
CVE-2022-35250MEDIUM4.3A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any auth...
CVE-2022-35249MEDIUM4.3A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method...
CVE-2022-35247MEDIUM4.3A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in th...
CVE-2022-35246MEDIUM4.3A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now