2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4651MEDIUM5.4The Justified Gallery WordPress plugin before 1.7.1 does not validate and escape one of its shortcode attributes, which ...
CVE-2022-4649MEDIUM5.4The WP Extended Search WordPress plugin before 2.1.2 does not validate and escape one of its shortcode attributes, which...
CVE-2022-4553MEDIUM4.3The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow a...
CVE-2022-4552MEDIUM6.1The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating its settings, and is missing saniti...
CVE-2022-4496MEDIUM6.1The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 be...
CVE-2022-4472MEDIUM5.4The Simple Sitemap WordPress plugin before 3.5.8 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4470MEDIUM5.4The Widgets for Google Reviews WordPress plugin before 9.8 does not validate and escape some of its shortcode attributes...
CVE-2022-4395CRITICAL9.8The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthe...
CVE-2022-4306MEDIUM5.4The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting ...
CVE-2022-26872HIGH8.8AMI Megarac Password reset interception via API
CVE-2022-23334CRITICAL9.8The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries...
CVE-2022-46087MEDIUM5.4CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin use...
CVE-2022-45788CRITICAL9.8A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code exe...
CVE-2022-42484CRITICAL9.8An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially...
CVE-2022-38451HIGH7.5A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially craf...
CVE-2022-2988HIGH7.5A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a mali...
CVE-2022-46359HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46358HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46357HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-46356HIGH8.8Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary...
CVE-2022-25967HIGH8.8Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine co...
CVE-2022-25936HIGH7.5Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the fi...
CVE-2022-48303MEDIUM5.5GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jum...
CVE-2022-27596CRITICAL9.8A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows ...
CVE-2022-48285HIGH7.3loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now