2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4627 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The ShiftNav WordPress plugin before 1.7.2 does not validate and escape some of its shortcode attributes before outputti... |
| CVE-2022-4625 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Login Logout Menu WordPress plugin before 1.4.0 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4624 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The GS Logo Slider WordPress plugin before 3.3.8 does not validate and escape some of its shortcode attributes before ou... |
| CVE-2022-4576 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Easy Bootstrap Shortcode WordPress plugin through 4.5.4 does not validate and escape some of its shortcode attribute... |
| CVE-2022-4570 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Top 10 WordPress plugin before 3.2.3 does not validate and escape some of its Block attributes before outputting the... |
| CVE-2022-4548 | MEDIUM | 6.5 | 0.3% | Jan 23, 2023 | The Optimize images ALT Text & names for SEO using AI WordPress plugin before 2.0.8 does not have CSRF check in place wh... |
| CVE-2022-4545 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Sitemap WordPress plugin before 4.4 does not validate and escape some of its shortcode attributes before outputting ... |
| CVE-2022-4542 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-4509 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before... |
| CVE-2022-4485 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Page-list WordPress plugin before 5.3 does not validate and escape some of its shortcode attributes before outputtin... |
| CVE-2022-4475 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Collapse-O-Matic WordPress plugin before 1.8.3 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4474 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4467 | MEDIUM | 5.4 | 0.5% | Jan 23, 2023 | The Search & Filter WordPress plugin before 1.2.16 does not validate and escape some of its shortcode attributes before ... |
| CVE-2022-4443 | MEDIUM | 6.5 | 0.3% | Jan 23, 2023 | The BruteBank WordPress plugin before 1.9 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-4383 | CRITICAL | 9.8 | 1.0% | Jan 23, 2023 | The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in... |
| CVE-2022-4346 | MEDIUM | 5.3 | 0.7% | Jan 23, 2023 | The All-In-One Security (AIOS) WordPress plugin before 5.1.3 leaked settings of the plugin publicly, including the used ... |
| CVE-2022-4323 | HIGH | 7.2 | 1.0% | Jan 23, 2023 | The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high... |
| CVE-2022-4307 | MEDIUM | 6.1 | 0.5% | Jan 23, 2023 | The پلاگین پرداخت دلخواه WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenti... |
| CVE-2022-4305 | CRITICAL | 9.8 | 38.6% | Jan 23, 2023 | The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to... |
| CVE-2022-4303 | HIGH | 7.5 | 0.7% | Jan 23, 2023 | The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers ... |
| CVE-2022-4230 | HIGH | 8.8 | 34.3% | Jan 23, 2023 | The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p... |
| CVE-2022-4017 | HIGH | 8.8 | 0.3% | Jan 23, 2023 | The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, B... |
| CVE-2022-47065 | HIGH | 8.8 | 1.1% | Jan 23, 2023 | TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow... |
| CVE-2022-41505 | MEDIUM | 6.4 | 0.4% | Jan 23, 2023 | An access control issue on TP-LInk Tapo C200 V1 devices allows physically proximate attackers to obtain root access by c... |
| CVE-2022-3811 | MEDIUM | 4.8 | 0.5% | Jan 23, 2023 | The EU Cookie Law for GDPR/CCPA WordPress plugin through 3.1.6 does not sanitise and escape some of its settings, which ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now