2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4719CRITICAL9.8Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4695MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4694MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4691MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4766MEDIUM6.5A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerabi...
CVE-2022-4755MEDIUM6.1A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file f...
CVE-2022-4748CRITICAL9.8A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of t...
CVE-2022-46764CRITICAL9.8A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated...
CVE-2022-46763HIGH8.8A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-p...
CVE-2022-36664MEDIUM6.1Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL...
CVE-2022-4268HIGH7.2The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL stateme...
CVE-2022-4267MEDIUM6.1The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting i...
CVE-2022-4266MEDIUM6.5The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could al...
CVE-2022-4243MEDIUM4.8The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-4242MEDIUM4.8The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could ...
CVE-2022-4239MEDIUM6.5The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request,...
CVE-2022-4227MEDIUM6.1The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, B...
CVE-2022-4226MEDIUM4.8The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which ...
CVE-2022-4197MEDIUM4.8The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-4166MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4165MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4164MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4163MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4162MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4161MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now