2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39039 | CRITICAL | 9.8 | 1.0% | Jan 3, 2023 | aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this... |
| CVE-2022-3614 | MEDIUM | 6.1 | 0.4% | Jan 3, 2023 | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa... |
| CVE-2022-3460 | HIGH | 7.5 | 0.6% | Jan 3, 2023 | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become u... |
| CVE-2022-4025 | MEDIUM | 4.3 | 0.5% | Jan 2, 2023 | Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-ori... |
| CVE-2022-3863 | MEDIUM | 6.1 | 0.4% | Jan 2, 2023 | Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo... |
| CVE-2022-3842 | HIGH | 7.5 | 18.3% | Jan 2, 2023 | Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the r... |
| CVE-2022-2743 | HIGH | 8.8 | 0.5% | Jan 2, 2023 | Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote atta... |
| CVE-2022-2742 | HIGH | 8.8 | 0.4% | Jan 2, 2023 | Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker wh... |
| CVE-2022-0801 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X... |
| CVE-2022-0337 | MEDIUM | 6.5 | 1.3% | Jan 2, 2023 | Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac... |
| CVE-2022-4417 | MEDIUM | 5.3 | 0.7% | Jan 2, 2023 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the RES... |
| CVE-2022-4381 | MEDIUM | 5.4 | 0.5% | Jan 2, 2023 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4373 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2022-4372 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2022-4371 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ... |
| CVE-2022-4370 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it i... |
| CVE-2022-4369 | MEDIUM | 6.1 | 0.5% | Jan 2, 2023 | The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting ... |
| CVE-2022-4362 | MEDIUM | 5.4 | 0.6% | Jan 2, 2023 | The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could... |
| CVE-2022-4360 | HIGH | 7.2 | 1.1% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4359 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4358 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ... |
| CVE-2022-4357 | CRITICAL | 9.8 | 1.0% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4356 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4355 | HIGH | 7.2 | 0.9% | Jan 2, 2023 | The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-4352 | HIGH | 7.2 | 1.0% | Jan 2, 2023 | The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now