2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38131MEDIUM6.1RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to r...
CVE-2022-34867MEDIUM6.5Unauthenticated Sensitive Information Disclosure vulnerability in WP Libre Form 2 plugin <= 2.0.8 at WordPress allows at...
CVE-2022-34656MEDIUM4.8Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting syste...
CVE-2022-33177MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress lead...
CVE-2022-2943MEDIUM4.9The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions ...
CVE-2022-2941MEDIUM4.8The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and i...
CVE-2022-2939MEDIUM5.3The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including...
CVE-2022-2936MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values...
CVE-2022-2935MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image U...
CVE-2022-2934MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image UR...
CVE-2022-2718MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v...
CVE-2022-2717MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v...
CVE-2022-2716MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Edi...
CVE-2022-2695MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption'...
CVE-2022-2518MEDIUM6.1The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to...
CVE-2022-2517MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption ...
CVE-2022-2516MEDIUM5.4The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page ...
CVE-2022-2515MEDIUM5.4The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code...
CVE-2022-2473MEDIUM4.8The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][tex...
CVE-2022-2462MEDIUM5.3The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenti...
CVE-2022-2461MEDIUM5.3The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate...
CVE-2022-2432MEDIUM4.3The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an...
CVE-2022-2430MEDIUM5.4The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Bloc...
CVE-2022-2402MEDIUM6.5The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kern...
CVE-2022-29062MEDIUM6.5Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now