2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4107 | MEDIUM | 6.5 | 0.4% | Dec 19, 2022 | The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as w... |
| CVE-2022-4106 | HIGH | 7.5 | 0.9% | Dec 19, 2022 | The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does no... |
| CVE-2022-4063 | CRITICAL | 9.8 | 9.5% | Dec 19, 2022 | The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, a... |
| CVE-2022-4061 | HIGH | 7.5 | 1.4% | Dec 19, 2022 | The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload function... |
| CVE-2022-4058 | MEDIUM | 5.4 | 0.2% | Dec 19, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting ... |
| CVE-2022-4050 | CRITICAL | 9.8 | 4.8% | Dec 19, 2022 | The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL s... |
| CVE-2022-4024 | MEDIUM | 6.5 | 0.3% | Dec 19, 2022 | The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an i... |
| CVE-2022-3987 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3986 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes be... |
| CVE-2022-3985 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3984 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes ... |
| CVE-2022-3983 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes bef... |
| CVE-2022-3961 | MEDIUM | 6.5 | 0.7% | Dec 19, 2022 | The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessi... |
| CVE-2022-3937 | MEDIUM | 5.4 | 0.5% | Dec 19, 2022 | The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow u... |
| CVE-2022-3832 | MEDIUM | 4.8 | 0.5% | Dec 19, 2022 | The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-4609 | MEDIUM | 5.4 | 0.7% | Dec 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0. |
| CVE-2022-40743 | MEDIUM | 6.1 | 1.1% | Dec 19, 2022 | Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can le... |
| CVE-2022-47500 | MEDIUM | 6.1 | 1.1% | Dec 19, 2022 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI componen... |
| CVE-2022-44755 | HIGH | 7.8 | 0.7% | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could ... |
| CVE-2022-44754 | HIGH | 7.8 | 0.6% | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could... |
| CVE-2022-44753 | HIGH | 7.8 | 0.6% | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could... |
| CVE-2022-44752 | HIGH | 7.8 | 0.6% | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This coul... |
| CVE-2022-44751 | HIGH | 7.8 | 0.6% | Dec 19, 2022 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could ... |
| CVE-2022-44750 | HIGH | 7.8 | 0.6% | Dec 19, 2022 | HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could... |
| CVE-2022-42453 | MEDIUM | 6.5 | 0.3% | Dec 19, 2022 | There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now