2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31075 | MEDIUM | 6.5 | 0.9% | Jul 11, 2022 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ... |
| CVE-2022-31074 | MEDIUM | 6.5 | 0.7% | Jul 11, 2022 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ... |
| CVE-2022-2123 | MEDIUM | 4.3 | 0.4% | Jul 11, 2022 | The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used ... |
| CVE-2022-2093 | MEDIUM | 4.8 | 0.5% | Jul 11, 2022 | The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h... |
| CVE-2022-2092 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting pa... |
| CVE-2022-2091 | MEDIUM | 6.5 | 0.4% | Jul 11, 2022 | The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any ... |
| CVE-2022-2089 | MEDIUM | 4.8 | 0.9% | Jul 11, 2022 | The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-2050 | MEDIUM | 4.8 | 0.5% | Jul 11, 2022 | The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user... |
| CVE-2022-1957 | MEDIUM | 4.3 | 0.4% | Jul 11, 2022 | The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co... |
| CVE-2022-1956 | MEDIUM | 4.3 | 0.3% | Jul 11, 2022 | The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its ... |
| CVE-2022-1951 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputt... |
| CVE-2022-1938 | MEDIUM | 5.4 | 0.6% | Jul 11, 2022 | The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate... |
| CVE-2022-1937 | MEDIUM | 6.1 | 1.4% | Jul 11, 2022 | The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an... |
| CVE-2022-1910 | MEDIUM | 6.1 | 1.2% | Jul 11, 2022 | The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter befor... |
| CVE-2022-1894 | MEDIUM | 4.8 | 0.5% | Jul 11, 2022 | The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high priv... |
| CVE-2022-1757 | MEDIUM | 5.4 | 0.3% | Jul 11, 2022 | The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow... |
| CVE-2022-1732 | MEDIUM | 6.5 | 0.5% | Jul 11, 2022 | The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login ... |
| CVE-2022-1626 | MEDIUM | 5.4 | 0.3% | Jul 11, 2022 | The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2022-1599 | MEDIUM | 6.5 | 0.6% | Jul 11, 2022 | The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowi... |
| CVE-2022-1576 | MEDIUM | 6.5 | 0.4% | Jul 11, 2022 | The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users l... |
| CVE-2022-1546 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before ... |
| CVE-2022-1474 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in... |
| CVE-2022-1220 | MEDIUM | 6.1 | 0.7% | Jul 11, 2022 | The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admi... |
| CVE-2022-1794 | MEDIUM | 5.5 | 0.2% | Jul 11, 2022 | The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is vi... |
| CVE-2022-35416 | MEDIUM | 6.1 | 2.6% | Jul 11, 2022 | H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now