2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1326MEDIUM4.8The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo...
CVE-2022-1321MEDIUM4.8The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, l...
CVE-2022-1113MEDIUM4.8The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which...
CVE-2022-1095MEDIUM4.8The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which cou...
CVE-2022-1029MEDIUM4.8The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to ma...
CVE-2022-1028MEDIUM4.8The WordPress Security Firewall, Malware Scanner, Secure Login and Backup plugin before 4.2.1 does not sanitise and esca...
CVE-2022-1010MEDIUM4.8The Login using WordPress Users ( WP as SAML IDP ) WordPress plugin before 1.13.4 does not sanitise and escape some of i...
CVE-2022-0875MEDIUM4.3The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s...
CVE-2022-0444MEDIUM4.3The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have auth...
CVE-2022-2213MEDIUM5.4A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected...
CVE-2022-33146MEDIUM6.1Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitra...
CVE-2022-34495MEDIUM5.5rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
CVE-2022-34494MEDIUM5.5rpmsg_virtio_add_ctrl_dev in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.
CVE-2022-29931MEDIUM6.1The administration interface of the Raytion Custom Security Manager (Raytion CSM) in Version 7.2.0 allows reflected Cros...
CVE-2022-31016MEDIUM6.5Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an un...
CVE-2022-29168MEDIUM6.1Wire is a secure messaging application. Wire is vulnerable to arbitrary HTML and Javascript execution via insufficient e...
CVE-2022-33122MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or...
CVE-2022-33910MEDIUM5.4An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports ...
CVE-2022-30028MEDIUM5.9Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset tok...
CVE-2022-29578MEDIUM5.3Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information s...
CVE-2022-29097MEDIUM4.9Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially expl...
CVE-2022-29096MEDIUM5.4Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigura...
CVE-2022-22389MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server m...
CVE-2022-33953MEDIUM4.6IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensit...
CVE-2022-29330MEDIUM4.9Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and S...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now