2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31373 | MEDIUM | 6.1 | 5.1% | Jun 21, 2022 | SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiCo... |
| CVE-2022-31307 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.... |
| CVE-2022-31306 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at s... |
| CVE-2022-31303 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2022-31302 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2022-31062 | MEDIUM | 5.3 | 5.5% | Jun 20, 2022 | ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ###... |
| CVE-2022-22414 | MEDIUM | 5.5 | 0.2% | Jun 20, 2022 | IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials... |
| CVE-2022-32983 | MEDIUM | 5.3 | 0.8% | Jun 20, 2022 | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filter... |
| CVE-2022-2134 | MEDIUM | 6.5 | 0.8% | Jun 20, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. |
| CVE-2022-25772 | MEDIUM | 6.1 | 61.2% | Jun 20, 2022 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers ... |
| CVE-2022-1945 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings... |
| CVE-2022-1915 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use... |
| CVE-2022-1896 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own... |
| CVE-2022-1895 | MEDIUM | 4.3 | 0.4% | Jun 20, 2022 | The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction ... |
| CVE-2022-1889 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow ... |
| CVE-2022-1832 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co... |
| CVE-2022-1831 | MEDIUM | 6.5 | 0.4% | Jun 20, 2022 | The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-1830 | MEDIUM | 6.5 | 0.4% | Jun 20, 2022 | The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,... |
| CVE-2022-1829 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1828 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2022-1827 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1826 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou... |
| CVE-2022-1818 | MEDIUM | 5.4 | 0.3% | Jun 20, 2022 | The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which ... |
| CVE-2022-1717 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its sett... |
| CVE-2022-1630 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now