2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4325MEDIUM6.1The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting ...
CVE-2022-4310MEDIUM6.1The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which c...
CVE-2022-4301MEDIUM6.1The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it bac...
CVE-2022-4196MEDIUM4.8The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allo...
CVE-2022-4103MEDIUM4.3The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a te...
CVE-2022-4102LOW3.1The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a te...
CVE-2022-4043HIGH7.2The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could...
CVE-2022-46603MEDIUM6.1An issue in Inkdrop v5.4.1 allows attackers to execute arbitrary commands via uploading a crafted markdown file.
CVE-2022-3923MEDIUM4.3The ActiveCampaign for WooCommerce WordPress plugin before 1.9.8 does not have authorisation check when cleaning up its ...
CVE-2022-3855MEDIUM4.8The 404 to Start WordPress plugin through 1.6.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3679HIGH8.8The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which c...
CVE-2022-3417HIGH8.8The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PH...
CVE-2022-3416HIGH7.2The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege use...
CVE-2022-3343LOW3.5The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer Discy WordPress th...
CVE-2022-43973HIGH7.2An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.1...
CVE-2022-43972HIGH7.5A null pointer dereference vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18....
CVE-2022-43971HIGH7.2An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <...
CVE-2022-43970HIGH7.2A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A st...
CVE-2022-36930HIGH7.8Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-...
CVE-2022-36929HIGH7.8The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr...
CVE-2022-36928HIGH7.1Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit t...
CVE-2022-36927HIGH7.8Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privi...
CVE-2022-36926HIGH7.8Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privi...
CVE-2022-36925HIGH7.8Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism. The encryption key used...
CVE-2022-4884MEDIUM4.9Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now