2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27676Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-27675Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-23832Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-23827Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-23816Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-43462HIGH7.2Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVE-2022-42462MEDIUM4.8Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVE-2022-30544HIGH8.8Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions.
CVE-2022-45440MEDIUM4.4A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbo...
CVE-2022-45439MEDIUM6.5A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC...
CVE-2022-3087HIGH7.8 Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to an out-of-bounds write which may al...
CVE-2022-4658MEDIUM5.4The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could a...
CVE-2022-4655MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, whic...
CVE-2022-4653MEDIUM5.4The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could a...
CVE-2022-4648MEDIUM5.4The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before...
CVE-2022-4578MEDIUM5.4The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attri...
CVE-2022-4571MEDIUM5.4The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attrib...
CVE-2022-4549MEDIUM4.3The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could al...
CVE-2022-4547HIGH7.2The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a par...
CVE-2022-4544MEDIUM5.4The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputt...
CVE-2022-4508MEDIUM5.4The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outpu...
CVE-2022-4507MEDIUM5.4The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes bef...
CVE-2022-4487MEDIUM5.4The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before ou...
CVE-2022-4486MEDIUM5.4The Meteor Slides WordPress plugin before 1.5.7 does not validate and escape some of its shortcode attributes before out...
CVE-2022-4484MEDIUM5.4The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.44 does not validate and escape s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now