2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4060CRITICAL9.8The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, makin...
CVE-2022-47630HIGH7.4Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects...
CVE-2022-3904MEDIUM6.1The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section...
CVE-2022-2658MEDIUM4.8The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users su...
CVE-2022-4890CRITICAL9.8A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some un...
CVE-2022-45438MEDIUM5.3When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat...
CVE-2022-43721MEDIUM5.4An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could ...
CVE-2022-43720MEDIUM5.4An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not ...
CVE-2022-43719HIGH8.8Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue a...
CVE-2022-43718MEDIUM5.4Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by aut...
CVE-2022-43717MEDIUM5.4Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vec...
CVE-2022-41703MEDIUM5.4A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a speci...
CVE-2022-4258HIGH7.8In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to ...
CVE-2022-4889CRITICAL9.8A vulnerability classified as critical was found in visegripped Stracker. Affected by this vulnerability is the function...
CVE-2022-2815MEDIUM6.5Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
CVE-2022-1812CRITICAL9.8Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.
CVE-2022-45353HIGH8.1Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
CVE-2022-38467MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
CVE-2022-38287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-41956MEDIUM6.5Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en...
CVE-2022-41955HIGH8.8Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en...
CVE-2022-23532MEDIUM6.5APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A...
CVE-2022-41721HIGH7.5A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP reque...
CVE-2022-46093HIGH8.2Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the ...
CVE-2022-45299CRITICAL9.8An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now