2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1326 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo... |
| CVE-2022-1321 | MEDIUM | 4.8 | 0.5% | Jun 27, 2022 | The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, l... |
| CVE-2022-1113 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which... |
| CVE-2022-1095 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which cou... |
| CVE-2022-1029 | MEDIUM | 4.8 | 0.8% | Jun 27, 2022 | The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma... |
| CVE-2022-1028 | MEDIUM | 4.8 | 0.5% | Jun 27, 2022 | The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and esca... |
| CVE-2022-1010 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of i... |
| CVE-2022-0875 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s... |
| CVE-2022-0444 | MEDIUM | 4.3 | 0.3% | Jun 27, 2022 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth... |
| CVE-2022-2213 | MEDIUM | 5.4 | 0.5% | Jun 27, 2022 | A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected... |
| CVE-2022-33146 | MEDIUM | 6.1 | 1.4% | Jun 27, 2022 | Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitra... |
| CVE-2022-34495 | MEDIUM | 5.5 | 0.3% | Jun 26, 2022 | rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free. |
| CVE-2022-34494 | MEDIUM | 5.5 | 0.3% | Jun 26, 2022 | rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free. |
| CVE-2022-29931 | MEDIUM | 6.1 | 0.5% | Jun 25, 2022 | The administration interface of the Raytion Custom Security Manager (Raytion CSM) in Version 7.2.0 allows reflected Cros... |
| CVE-2022-31016 | MEDIUM | 6.5 | 0.8% | Jun 25, 2022 | Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an un... |
| CVE-2022-29168 | MEDIUM | 6.1 | 0.8% | Jun 25, 2022 | Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient e... |
| CVE-2022-33122 | MEDIUM | 4.8 | 0.5% | Jun 24, 2022 | A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-33910 | MEDIUM | 5.4 | 0.9% | Jun 24, 2022 | An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports ... |
| CVE-2022-30028 | MEDIUM | 5.9 | 0.5% | Jun 24, 2022 | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset tok... |
| CVE-2022-29578 | MEDIUM | 5.3 | 1.0% | Jun 24, 2022 | Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information s... |
| CVE-2022-29097 | MEDIUM | 4.9 | 1.2% | Jun 24, 2022 | Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially expl... |
| CVE-2022-29096 | MEDIUM | 5.4 | 0.5% | Jun 24, 2022 | Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigura... |
| CVE-2022-22389 | MEDIUM | 6.5 | 1.5% | Jun 24, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server m... |
| CVE-2022-33953 | MEDIUM | 4.6 | 0.3% | Jun 24, 2022 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensit... |
| CVE-2022-29330 | MEDIUM | 4.9 | 0.9% | Jun 24, 2022 | Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and S... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now