2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1800 | HIGH | 7.2 | 1.2% | Jun 13, 2022 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp... |
| CVE-2022-1791 | HIGH | 8.1 | 0.5% | Jun 13, 2022 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting... |
| CVE-2022-1779 | HIGH | 8.1 | 0.5% | Jun 13, 2022 | The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1777 | HIGH | 8.8 | 1.2% | Jun 13, 2022 | The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to ... |
| CVE-2022-1765 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image... |
| CVE-2022-1762 | HIGH | 7.5 | 1.2% | Jun 13, 2022 | The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origi... |
| CVE-2022-1758 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin... |
| CVE-2022-1412 | HIGH | 7.5 | 1.4% | Jun 13, 2022 | The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen... |
| CVE-2022-1202 | HIGH | 7.8 | 1.0% | Jun 13, 2022 | The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea... |
| CVE-2022-0863 | HIGH | 7.2 | 22.4% | Jun 13, 2022 | The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high ... |
| CVE-2022-2064 | HIGH | 8.8 | 1.1% | Jun 13, 2022 | Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-2063 | HIGH | 8.8 | 1.3% | Jun 13, 2022 | Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-2062 | HIGH | 7.5 | 1.5% | Jun 13, 2022 | Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-28704 | HIGH | 7.2 | 2.4% | Jun 13, 2022 | Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log... |
| CVE-2022-26834 | HIGH | 7.5 | 1.4% | Jun 13, 2022 | Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obt... |
| CVE-2022-2013 | HIGH | 7.5 | 0.8% | Jun 13, 2022 | In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental f... |
| CVE-2022-2054 | HIGH | 7.8 | 0.5% | Jun 12, 2022 | Code Injection in GitHub repository nuitka/nuitka prior to 0.9. |
| CVE-2022-30780 | HIGH | 7.5 | 56.4% | Jun 11, 2022 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connect... |
| CVE-2022-32981 | HIGH | 7.8 | 1.0% | Jun 10, 2022 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in pt... |
| CVE-2022-29094 | HIGH | 7.1 | 0.2% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-29093 | HIGH | 7.1 | 0.2% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-29092 | HIGH | 7.8 | 0.4% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-25851 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause ... |
| CVE-2022-24429 | HIGH | 7.8 | 0.8% | Jun 10, 2022 | The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG ... |
| CVE-2022-21211 | HIGH | 7.5 | 0.9% | Jun 10, 2022 | This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the val... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now