2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35655 | MEDIUM | 6.1 | 0.4% | Aug 22, 2022 | Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. |
| CVE-2022-35654 | MEDIUM | 6.1 | 0.4% | Aug 22, 2022 | Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |
| CVE-2022-34857 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr... |
| CVE-2022-34774 | MEDIUM | 5.3 | 0.4% | Aug 22, 2022 | Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can m... |
| CVE-2022-2873 | MEDIUM | 5.5 | 0.3% | Aug 22, 2022 | An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a... |
| CVE-2022-2600 | MEDIUM | 5.4 | 0.5% | Aug 22, 2022 | The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which c... |
| CVE-2022-2558 | MEDIUM | 5.3 | 0.8% | Aug 22, 2022 | The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing ... |
| CVE-2022-2555 | MEDIUM | 6.5 | 0.4% | Aug 22, 2022 | The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which cou... |
| CVE-2022-2552 | MEDIUM | 5.3 | 8.4% | Aug 22, 2022 | The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information a... |
| CVE-2022-2532 | MEDIUM | 6.1 | 0.6% | Aug 22, 2022 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2022-2407 | MEDIUM | 4.8 | 0.6% | Aug 22, 2022 | The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege... |
| CVE-2022-2392 | MEDIUM | 6.5 | 0.9% | Aug 22, 2022 | The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that ca... |
| CVE-2022-2389 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami Wor... |
| CVE-2022-2388 | MEDIUM | 6.5 | 0.4% | Aug 22, 2022 | The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, w... |
| CVE-2022-2383 | MEDIUM | 6.1 | 4.9% | Aug 22, 2022 | The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in... |
| CVE-2022-2382 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some o... |
| CVE-2022-2377 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing an... |
| CVE-2022-2375 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings,... |
| CVE-2022-2361 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-2312 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing a... |
| CVE-2022-2276 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow... |
| CVE-2022-2275 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make... |
| CVE-2022-2198 | MEDIUM | 4.3 | 0.6% | Aug 22, 2022 | The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author... |
| CVE-2022-2172 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logge... |
| CVE-2022-25810 | MEDIUM | 6.5 | 0.9% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_re... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now