2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4160MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4159MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4158HIGH7.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4157MEDIUM4.9The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4156HIGH7.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4155MEDIUM4.9The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4154MEDIUM4.9The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating...
CVE-2022-4153MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4152MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the...
CVE-2022-4151MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4150MEDIUM6.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4120CRITICAL9.8The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user...
CVE-2022-4117CRITICAL9.8The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX...
CVE-2022-4110MEDIUM4.8The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-4047CRITICAL9.8The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be up...
CVE-2022-4042MEDIUM4.8The Paytium: Mollie payment forms & donations WordPress plugin before 4.3.7 does not sanitise and escape some of its set...
CVE-2022-3840MEDIUM4.8The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could a...
CVE-2022-3835MEDIUM4.8The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-4742CRITICAL9.8A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is...
CVE-2022-41767MEDIUM5.3An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When chan...
CVE-2022-41765MEDIUM5.3An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserT...
CVE-2022-30260HIGH7.8Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate check...
CVE-2022-26969CRITICAL9.8In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
CVE-2022-26964HIGH7.5Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure vi...
CVE-2022-24120MEDIUM4.6Certain General Electric Renewable Energy products store cleartext credentials in flash memory. This affects iNET and iN...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now