2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35655MEDIUM6.1Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
CVE-2022-35654MEDIUM6.1Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
CVE-2022-34857MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPr...
CVE-2022-34774MEDIUM5.3Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can m...
CVE-2022-2873MEDIUM5.5An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a...
CVE-2022-2600MEDIUM5.4The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which c...
CVE-2022-2558MEDIUM5.3The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing ...
CVE-2022-2555MEDIUM6.5The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which cou...
CVE-2022-2552MEDIUM5.3The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information a...
CVE-2022-2532MEDIUM6.1The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-2407MEDIUM4.8The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege...
CVE-2022-2392MEDIUM6.5The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that ca...
CVE-2022-2389MEDIUM4.3The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami Wor...
CVE-2022-2388MEDIUM6.5The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, w...
CVE-2022-2383MEDIUM6.1The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-2382MEDIUM4.3The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some o...
CVE-2022-2377MEDIUM4.3The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing an...
CVE-2022-2375MEDIUM5.4The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings,...
CVE-2022-2361MEDIUM4.8The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-2312MEDIUM5.4The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing a...
CVE-2022-2276MEDIUM4.3The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow...
CVE-2022-2275MEDIUM4.3The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make...
CVE-2022-2198MEDIUM4.3The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author...
CVE-2022-2172MEDIUM4.3The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logge...
CVE-2022-25810MEDIUM6.5The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_re...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now