2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2072MEDIUM6.1The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in ...
CVE-2022-2071MEDIUM6.1The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking san...
CVE-2022-1551MEDIUM6.5The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad ac...
CVE-2022-0899MEDIUM6.1The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back...
CVE-2022-0594MEDIUM5.3The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author...
CVE-2022-36414MEDIUM6.7There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 t...
CVE-2022-1146MEDIUM6.5Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to lea...
CVE-2022-1139MEDIUM6.5Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker t...
CVE-2022-1138MEDIUM6.5Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had com...
CVE-2022-1137MEDIUM6.5Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a u...
CVE-2022-1132MEDIUM6.1Inappropriate implementation in Virtual Keyboard in Google Chrome on Chrome OS prior to 100.0.4896.60 allowed a local at...
CVE-2022-1129MEDIUM6.5Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896.60 allowed a remote att...
CVE-2022-1128MEDIUM6.5Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on ...
CVE-2022-34112MEDIUM6.5An access control issue in the component /api/plugin/uninstall Dataease v1.11.1 allows attackers to arbitrarily uninstal...
CVE-2022-34853MEDIUM5.4Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax ...
CVE-2022-34650MEDIUM5.4Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team...
CVE-2022-33191MEDIUM5.4Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Chinmoy Paul's Testim...
CVE-2022-29495MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacke...
CVE-2022-2511MEDIUM6.1Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to injec...
CVE-2022-2510MEDIUM6.1Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to ...
CVE-2022-34520MEDIUM5.5Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/b...
CVE-2022-34503MEDIUM6.5QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerabilit...
CVE-2022-34502MEDIUM5.5Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm...
CVE-2022-2470MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2142MEDIUM5.9The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attac...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now