2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26426 | MEDIUM | 6.7 | 0.1% | Aug 1, 2022 | In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2022-21792 | MEDIUM | 6.7 | 0.1% | Aug 1, 2022 | In camera isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2022-21791 | MEDIUM | 4.4 | 0.1% | Aug 1, 2022 | In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio... |
| CVE-2022-21790 | MEDIUM | 4.4 | 0.1% | Aug 1, 2022 | In camera isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio... |
| CVE-2022-21789 | MEDIUM | 6.4 | 0.1% | Aug 1, 2022 | In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of priv... |
| CVE-2022-21788 | MEDIUM | 6.7 | 0.1% | Aug 1, 2022 | In scp, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of p... |
| CVE-2022-2370 | MEDIUM | 6.5 | 0.7% | Aug 1, 2022 | The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS ... |
| CVE-2022-2369 | MEDIUM | 4.3 | 0.6% | Aug 1, 2022 | The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users... |
| CVE-2022-2328 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The Flexi Quote Rotator WordPress plugin through 0.9.4 does not sanitise and escape its settings, allowing high privileg... |
| CVE-2022-2325 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, wh... |
| CVE-2022-2305 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allo... |
| CVE-2022-2278 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not validate, sanitise and escape some of its sett... |
| CVE-2022-2260 | MEDIUM | 6.5 | 0.4% | Aug 1, 2022 | The GiveWP WordPress plugin before 2.21.3 does not have CSRF in place when exporting data, and does not validate the exp... |
| CVE-2022-2241 | MEDIUM | 6.1 | 0.5% | Aug 1, 2022 | The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its set... |
| CVE-2022-2215 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow... |
| CVE-2022-2181 | MEDIUM | 6.1 | 0.5% | Aug 1, 2022 | The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back... |
| CVE-2022-2171 | MEDIUM | 5.4 | 0.3% | Aug 1, 2022 | The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could a... |
| CVE-2022-2170 | MEDIUM | 4.8 | 1.1% | Aug 1, 2022 | The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its ... |
| CVE-2022-26308 | MEDIUM | 5.4 | 0.3% | Aug 1, 2022 | Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with... |
| CVE-2022-1906 | MEDIUM | 6.1 | 0.9% | Aug 1, 2022 | The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via... |
| CVE-2022-1600 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOT... |
| CVE-2022-1561 | MEDIUM | 4.3 | 0.5% | Aug 1, 2022 | Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters ... |
| CVE-2022-1324 | MEDIUM | 4.8 | 0.5% | Aug 1, 2022 | The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-pri... |
| CVE-2022-0598 | MEDIUM | 4.8 | 0.6% | Aug 1, 2022 | The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow... |
| CVE-2022-35716 | MEDIUM | 6.5 | 0.5% | Aug 1, 2022 | IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 thro... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now