2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31075MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2022-31074MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2022-2123MEDIUM4.3The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used ...
CVE-2022-2093MEDIUM4.8The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h...
CVE-2022-2092MEDIUM6.1The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting pa...
CVE-2022-2091MEDIUM6.5The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any ...
CVE-2022-2089MEDIUM4.8The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow...
CVE-2022-2050MEDIUM4.8The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user...
CVE-2022-1957MEDIUM4.3The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co...
CVE-2022-1956MEDIUM4.3The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its ...
CVE-2022-1951MEDIUM6.1The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputt...
CVE-2022-1938MEDIUM5.4The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate...
CVE-2022-1937MEDIUM6.1The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an...
CVE-2022-1910MEDIUM6.1The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter befor...
CVE-2022-1894MEDIUM4.8The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high priv...
CVE-2022-1757MEDIUM5.4The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow...
CVE-2022-1732MEDIUM6.5The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login ...
CVE-2022-1626MEDIUM5.4The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could al...
CVE-2022-1599MEDIUM6.5The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowi...
CVE-2022-1576MEDIUM6.5The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users l...
CVE-2022-1546MEDIUM6.1The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before ...
CVE-2022-1474MEDIUM6.1The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in...
CVE-2022-1220MEDIUM6.1The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admi...
CVE-2022-1794MEDIUM5.5The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is vi...
CVE-2022-35416MEDIUM6.1H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now