2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2101MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter...
CVE-2022-22304MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent fo...
CVE-2022-2400MEDIUM5.3External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-23142MEDIUM5.3ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short ...
CVE-2022-30625MEDIUM5.3Directory listing is a web server function that displays the directory contents when there is no index file in a specifi...
CVE-2022-30621MEDIUM6.5Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS a...
CVE-2022-24692MEDIUM5.4An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page ...
CVE-2022-24689MEDIUM5.3An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote atta...
CVE-2022-31202MEDIUM6.5The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via e...
CVE-2022-31201MEDIUM5.4SoftGuard Web (SGW) before 5.1.5 allows HTML injection.
CVE-2022-30982MEDIUM5.4An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username...
CVE-2022-27930MEDIUM5.9Pexip Infinity 27.x before 27.3 allows remote attackers to trigger a software abort via single-sign-on if a random Unive...
CVE-2022-25357MEDIUM5.3Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a conference (call join) if ...
CVE-2022-31260MEDIUM6.5In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows attackers to export collectio...
CVE-2022-2222MEDIUM4.9The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold...
CVE-2022-2194MEDIUM4.8The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing hi...
CVE-2022-2187MEDIUM6.1The Contact Form 7 Captcha WordPress plugin before 0.1.2 does not escape the $_SERVER['REQUEST_URI'] parameter before ou...
CVE-2022-2186MEDIUM4.8The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege u...
CVE-2022-2173MEDIUM6.1The Advanced Database Cleaner WordPress plugin before 3.1.1 does not escape numerous generated URLs before outputting th...
CVE-2022-2169MEDIUM4.8The Loading Page with Loading Screen WordPress plugin before 1.0.83 does not escape its settings, allowing high privileg...
CVE-2022-2168MEDIUM6.1The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attr...
CVE-2022-2151MEDIUM4.8The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing ...
CVE-2022-2149MEDIUM4.8The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile...
CVE-2022-2148MEDIUM4.8The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high pri...
CVE-2022-2146MEDIUM6.1The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them bac...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now