2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2144 | MEDIUM | 4.3 | 0.4% | Jul 17, 2022 | The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its... |
| CVE-2022-2133 | MEDIUM | 5.3 | 1.0% | Jul 17, 2022 | The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate... |
| CVE-2022-2118 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as ad... |
| CVE-2022-2114 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table se... |
| CVE-2022-2100 | MEDIUM | 4.8 | 0.5% | Jul 17, 2022 | The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege user... |
| CVE-2022-2099 | MEDIUM | 4.8 | 0.6% | Jul 17, 2022 | The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitiz... |
| CVE-2022-2090 | MEDIUM | 6.1 | 0.7% | Jul 17, 2022 | The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back i... |
| CVE-2022-1933 | MEDIUM | 6.1 | 1.3% | Jul 17, 2022 | The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response... |
| CVE-2022-25869 | MEDIUM | 6.1 | 5.3% | Jul 15, 2022 | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs a... |
| CVE-2022-31159 | MEDIUM | 6.5 | 1.2% | Jul 15, 2022 | The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists wit... |
| CVE-2022-31153 | MEDIUM | 6.5 | 1.1% | Jul 15, 2022 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK... |
| CVE-2022-34252 | MEDIUM | 5.5 | 0.3% | Jul 15, 2022 | Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability th... |
| CVE-2022-34248 | MEDIUM | 5.5 | 0.4% | Jul 15, 2022 | Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerabilit... |
| CVE-2022-34244 | MEDIUM | 5.5 | 0.4% | Jul 15, 2022 | Adobe Photoshop versions 22.5.7 (and earlier) and 23.3.2 (and earlier) are affected by an Access of Uninitialized Pointe... |
| CVE-2022-34239 | MEDIUM | 5.5 | 2.9% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-34237 | MEDIUM | 5.5 | 3.0% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-34236 | MEDIUM | 5.5 | 3.0% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-34234 | MEDIUM | 5.5 | 3.1% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-34233 | MEDIUM | 5.5 | 4.2% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-34232 | MEDIUM | 5.5 | 3.1% | Jul 15, 2022 | Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are ... |
| CVE-2022-23201 | MEDIUM | 6.1 | 0.6% | Jul 15, 2022 | Adobe RoboHelp versions 2020.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a... |
| CVE-2022-34826 | MEDIUM | 5.9 | 0.5% | Jul 15, 2022 | In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. |
| CVE-2022-32118 | MEDIUM | 6.1 | 0.9% | Jul 15, 2022 | Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory p... |
| CVE-2022-30245 | MEDIUM | 6.5 | 1.0% | Jul 15, 2022 | Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables co... |
| CVE-2022-30242 | MEDIUM | 6.8 | 1.0% | Jul 15, 2022 | Honeywell Alerton Ascent Control Module (ACM) through 2022-05-04 allows unauthenticated configuration changes from remot... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now