2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4719 | CRITICAL | 9.8 | 1.0% | Dec 27, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5. |
| CVE-2022-4695 | MEDIUM | 5.4 | 0.7% | Dec 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-4694 | MEDIUM | 5.4 | 0.5% | Dec 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-4691 | MEDIUM | 5.4 | 0.7% | Dec 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-4766 | MEDIUM | 6.5 | 0.3% | Dec 27, 2022 | A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerabi... |
| CVE-2022-4755 | MEDIUM | 6.1 | 0.5% | Dec 27, 2022 | A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file f... |
| CVE-2022-4748 | CRITICAL | 9.8 | 0.9% | Dec 27, 2022 | A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of t... |
| CVE-2022-46764 | CRITICAL | 9.8 | 2.1% | Dec 27, 2022 | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated... |
| CVE-2022-46763 | HIGH | 8.8 | 1.1% | Dec 27, 2022 | A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-p... |
| CVE-2022-36664 | MEDIUM | 6.1 | 3.8% | Dec 26, 2022 | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL... |
| CVE-2022-4268 | HIGH | 7.2 | 1.1% | Dec 26, 2022 | The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL stateme... |
| CVE-2022-4267 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting i... |
| CVE-2022-4266 | MEDIUM | 6.5 | 0.3% | Dec 26, 2022 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could al... |
| CVE-2022-4243 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2022-4242 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The WP Google Review Slider WordPress plugin before 11.6 does not sanitise and escape some of its settings, which could ... |
| CVE-2022-4239 | MEDIUM | 6.5 | 0.6% | Dec 26, 2022 | The Workreap WordPress theme before 2.6.4 does not verify that an addon service belongs to the user issuing the request,... |
| CVE-2022-4227 | MEDIUM | 6.1 | 0.4% | Dec 26, 2022 | The Booster for WooCommerce WordPress plugin before 5.6.3, Booster Plus for WooCommerce WordPress plugin before 6.0.0, B... |
| CVE-2022-4226 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which ... |
| CVE-2022-4197 | MEDIUM | 4.8 | 0.5% | Dec 26, 2022 | The Sliderby10Web WordPress plugin before 1.2.53 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-4166 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4165 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4164 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4163 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4162 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
| CVE-2022-4161 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now