2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39039CRITICAL9.8aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this...
CVE-2022-3614MEDIUM6.1In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypa...
CVE-2022-3460HIGH7.5In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become u...
CVE-2022-4025MEDIUM4.3Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-ori...
CVE-2022-3863MEDIUM6.1Use after free in Browser History in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially explo...
CVE-2022-3842HIGH7.5Use after free in Passwords in Google Chrome prior to 105.0.5195.125 allowed a remote attacker who had compromised the r...
CVE-2022-2743HIGH8.8Integer overflow in Window Manager in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote atta...
CVE-2022-2742HIGH8.8Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker wh...
CVE-2022-0801MEDIUM6.1Inappropriate implementation in HTML parser in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass X...
CVE-2022-0337MEDIUM6.5Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attac...
CVE-2022-4417MEDIUM5.3The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the RES...
CVE-2022-4381MEDIUM5.4The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could...
CVE-2022-4373HIGH7.2The Quote-O-Matic WordPress plugin through 1.0.5 does not properly sanitize and escape a parameter before using it in a ...
CVE-2022-4372HIGH7.2The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ...
CVE-2022-4371HIGH7.2The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQ...
CVE-2022-4370HIGH7.2The multimedial images WordPress plugin through 1.0b does not properly sanitize and escape a parameter before using it i...
CVE-2022-4369MEDIUM6.1The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting ...
CVE-2022-4362MEDIUM5.4The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could...
CVE-2022-4360HIGH7.2The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ...
CVE-2022-4359HIGH7.2The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ...
CVE-2022-4358HIGH7.2The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it ...
CVE-2022-4357CRITICAL9.8The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-4356HIGH7.2The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-4355HIGH7.2The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-4352HIGH7.2The Qe SEO Handyman WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now