2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-1800HIGH7.2The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp...
CVE-2022-1791HIGH8.1The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting...
CVE-2022-1779HIGH8.1The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which...
CVE-2022-1777HIGH8.8The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to ...
CVE-2022-1765HIGH8.8The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image...
CVE-2022-1762HIGH7.5The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origi...
CVE-2022-1758HIGH8.8The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin...
CVE-2022-1412HIGH7.5The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen...
CVE-2022-1202HIGH7.8The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea...
CVE-2022-0863HIGH7.2The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high ...
CVE-2022-2064HIGH8.8Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2063HIGH8.8Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2062HIGH7.5Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-28704HIGH7.2Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log...
CVE-2022-26834HIGH7.5Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obt...
CVE-2022-2013HIGH7.5In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental f...
CVE-2022-2054HIGH7.8Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
CVE-2022-30780HIGH7.5Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connect...
CVE-2022-32981HIGH7.8An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in pt...
CVE-2022-29094HIGH7.1Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-29093HIGH7.1Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-29092HIGH7.8Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-25851HIGH7.5The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause ...
CVE-2022-24429HIGH7.8The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG ...
CVE-2022-21211HIGH7.5This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the val...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now