2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2072 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2022-2071 | MEDIUM | 6.1 | 0.3% | Jul 25, 2022 | The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking san... |
| CVE-2022-1551 | MEDIUM | 6.5 | 0.8% | Jul 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad ac... |
| CVE-2022-0899 | MEDIUM | 6.1 | 1.0% | Jul 25, 2022 | The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back... |
| CVE-2022-0594 | MEDIUM | 5.3 | 1.5% | Jul 25, 2022 | The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author... |
| CVE-2022-36414 | MEDIUM | 6.7 | 0.2% | Jul 23, 2022 | There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 t... |
| CVE-2022-1146 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to lea... |
| CVE-2022-1139 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker t... |
| CVE-2022-1138 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had com... |
| CVE-2022-1137 | MEDIUM | 6.5 | 0.5% | Jul 23, 2022 | Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a u... |
| CVE-2022-1132 | MEDIUM | 6.1 | 0.3% | Jul 23, 2022 | Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local at... |
| CVE-2022-1129 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote att... |
| CVE-2022-1128 | MEDIUM | 6.5 | 0.6% | Jul 23, 2022 | Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on ... |
| CVE-2022-34112 | MEDIUM | 6.5 | 0.5% | Jul 22, 2022 | An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstal... |
| CVE-2022-34853 | MEDIUM | 5.4 | 0.4% | Jul 22, 2022 | Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax ... |
| CVE-2022-34650 | MEDIUM | 5.4 | 0.4% | Jul 22, 2022 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team... |
| CVE-2022-33191 | MEDIUM | 5.4 | 0.4% | Jul 22, 2022 | Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testim... |
| CVE-2022-29495 | MEDIUM | 4.3 | 0.4% | Jul 22, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacke... |
| CVE-2022-2511 | MEDIUM | 6.1 | 0.4% | Jul 22, 2022 | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to injec... |
| CVE-2022-2510 | MEDIUM | 6.1 | 0.4% | Jul 22, 2022 | Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to ... |
| CVE-2022-34520 | MEDIUM | 5.5 | 0.3% | Jul 22, 2022 | Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/b... |
| CVE-2022-34503 | MEDIUM | 6.5 | 0.7% | Jul 22, 2022 | QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerabilit... |
| CVE-2022-34502 | MEDIUM | 5.5 | 0.3% | Jul 22, 2022 | Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm... |
| CVE-2022-2470 | MEDIUM | 6.1 | 0.8% | Jul 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. |
| CVE-2022-2142 | MEDIUM | 5.9 | 0.7% | Jul 22, 2022 | The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now