2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3025 | MEDIUM | 5.4 | 0.2% | Sep 26, 2022 | The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allow... |
| CVE-2022-3024 | MEDIUM | 5.4 | 0.2% | Sep 26, 2022 | The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, al... |
| CVE-2022-2926 | MEDIUM | 4.9 | 1.3% | Sep 26, 2022 | The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privil... |
| CVE-2022-2405 | MEDIUM | 4.3 | 0.3% | Sep 26, 2022 | The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowin... |
| CVE-2022-2404 | MEDIUM | 6.1 | 0.5% | Sep 26, 2022 | The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2022-1755 | MEDIUM | 5.4 | 0.5% | Sep 26, 2022 | The SVG Support WordPress plugin before 2.5 does not properly handle SVG added via an URL, which could allow users with ... |
| CVE-2022-1613 | MEDIUM | 5.3 | 0.6% | Sep 26, 2022 | The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers ov... |
| CVE-2022-38970 | MEDIUM | 6.5 | 1.0% | Sep 26, 2022 | ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs ... |
| CVE-2022-38553 | MEDIUM | 6.1 | 2.3% | Sep 26, 2022 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulner... |
| CVE-2022-21169 | MEDIUM | 6.1 | 0.7% | Sep 26, 2022 | The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allo... |
| CVE-2022-23461 | MEDIUM | 6.1 | 0.5% | Sep 24, 2022 | Jodit Editor is a WYSIWYG editor written in pure TypeScript without the use of additional libraries. Jodit Editor is vul... |
| CVE-2022-39242 | MEDIUM | 5.3 | 0.6% | Sep 24, 2022 | Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the... |
| CVE-2022-39240 | MEDIUM | 5.4 | 0.6% | Sep 24, 2022 | MyGraph is a permission management system. Versions prior to 1.0.4 are vulnerable to a storage XSS vulnerability leading... |
| CVE-2022-3278 | MEDIUM | 5.5 | 0.8% | Sep 23, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. |
| CVE-2022-40132 | MEDIUM | 4.3 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Seriously Simple Podcasting plugin <= 2.16.0 at WordPress, leading to... |
| CVE-2022-40103 | MEDIUM | 5.5 | 0.2% | Sep 23, 2022 | Tenda i9 v1.0.0.8(3828) was discovered to contain a buffer overflow via the formSetAutoPing function. This vulnerability... |
| CVE-2022-38704 | MEDIUM | 4.3 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 40... |
| CVE-2022-38439 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi... |
| CVE-2022-38438 | MEDIUM | 5.4 | 0.7% | Sep 23, 2022 | Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi... |
| CVE-2022-36340 | MEDIUM | 5.3 | 0.6% | Sep 23, 2022 | Unauthenticated Optin Campaign Cache Deletion vulnerability in MailOptin plugin <= 1.2.49.0 at WordPress. |
| CVE-2022-35251 | MEDIUM | 5.4 | 0.5% | Sep 23, 2022 | A cross-site scripting vulnerability exists in Rocket.chat <v5 due to style injection in the complete chat window, an ad... |
| CVE-2022-35250 | MEDIUM | 4.3 | 0.6% | Sep 23, 2022 | A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any auth... |
| CVE-2022-35249 | MEDIUM | 4.3 | 0.6% | Sep 23, 2022 | A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method... |
| CVE-2022-35247 | MEDIUM | 4.3 | 0.5% | Sep 23, 2022 | A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in th... |
| CVE-2022-35246 | MEDIUM | 4.3 | 0.6% | Sep 23, 2022 | A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now