2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4107MEDIUM6.5The SMSA Shipping for WooCommerce WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks, as w...
CVE-2022-4106HIGH7.5The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does no...
CVE-2022-4063CRITICAL9.8The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, a...
CVE-2022-4061HIGH7.5The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload function...
CVE-2022-4058MEDIUM5.4The Photo Gallery by 10Web WordPress plugin before 1.8.3 does not validate and escape some parameters before outputting ...
CVE-2022-4050CRITICAL9.8The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL s...
CVE-2022-4024MEDIUM6.5The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an i...
CVE-2022-3987MEDIUM5.4The Responsive Lightbox2 WordPress plugin before 1.0.4 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3986MEDIUM5.4The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes be...
CVE-2022-3985MEDIUM5.4The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3984MEDIUM5.4The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes ...
CVE-2022-3983MEDIUM5.4The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes bef...
CVE-2022-3961MEDIUM6.5The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessi...
CVE-2022-3937MEDIUM5.4The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow u...
CVE-2022-3832MEDIUM4.8The External Media WordPress plugin before 1.0.36 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-4609MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-40743MEDIUM6.1Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can le...
CVE-2022-47500MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI componen...
CVE-2022-44755HIGH7.8HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could ...
CVE-2022-44754HIGH7.8HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could...
CVE-2022-44753HIGH7.8HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could...
CVE-2022-44752HIGH7.8HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This coul...
CVE-2022-44751HIGH7.8HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could ...
CVE-2022-44750HIGH7.8HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could...
CVE-2022-42453MEDIUM6.5There are insufficient warnings when a Fixlet is imported by a user. The warning message currently assumes the owner of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now