2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2101 | MEDIUM | 5.4 | 0.8% | Jul 18, 2022 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter... |
| CVE-2022-22304 | MEDIUM | 6.1 | 0.5% | Jul 18, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent fo... |
| CVE-2022-2400 | MEDIUM | 5.3 | 0.9% | Jul 18, 2022 | External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0. |
| CVE-2022-23142 | MEDIUM | 5.3 | 0.6% | Jul 18, 2022 | ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short ... |
| CVE-2022-30625 | MEDIUM | 5.3 | 0.3% | Jul 18, 2022 | Directory listing is a web server function that displays the directory contents when there is no index file in a specifi... |
| CVE-2022-30621 | MEDIUM | 6.5 | 0.6% | Jul 18, 2022 | Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS a... |
| CVE-2022-24692 | MEDIUM | 5.4 | 0.5% | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page ... |
| CVE-2022-24689 | MEDIUM | 5.3 | 0.8% | Jul 18, 2022 | An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote atta... |
| CVE-2022-31202 | MEDIUM | 6.5 | 1.2% | Jul 17, 2022 | The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via e... |
| CVE-2022-31201 | MEDIUM | 5.4 | 0.5% | Jul 17, 2022 | SoftGuard Web (SGW) before 5.1.5 allows HTML injection. |
| CVE-2022-30982 | MEDIUM | 5.4 | 0.5% | Jul 17, 2022 | An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username... |
| CVE-2022-27930 | MEDIUM | 5.9 | 0.8% | Jul 17, 2022 | Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Unive... |
| CVE-2022-25357 | MEDIUM | 5.3 | 0.6% | Jul 17, 2022 | Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if ... |
| CVE-2022-31260 | MEDIUM | 6.5 | 1.5% | Jul 17, 2022 | In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio... |
| CVE-2022-2222 | MEDIUM | 4.9 | 0.9% | Jul 17, 2022 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold... |
| CVE-2022-2194 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing hi... |
| CVE-2022-2187 | MEDIUM | 6.1 | 1.3% | Jul 17, 2022 | The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou... |
| CVE-2022-2186 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege u... |
| CVE-2022-2173 | MEDIUM | 6.1 | 0.7% | Jul 17, 2022 | The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th... |
| CVE-2022-2169 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg... |
| CVE-2022-2168 | MEDIUM | 6.1 | 1.1% | Jul 17, 2022 | The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr... |
| CVE-2022-2151 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing ... |
| CVE-2022-2149 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile... |
| CVE-2022-2148 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high pri... |
| CVE-2022-2146 | MEDIUM | 6.1 | 0.3% | Jul 17, 2022 | The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them bac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now