2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31373MEDIUM6.1SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiCo...
CVE-2022-31307MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string....
CVE-2022-31306MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at s...
CVE-2022-31303MEDIUM5.4maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-31302MEDIUM5.4maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-31062MEDIUM5.3### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ###...
CVE-2022-22414MEDIUM5.5IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials...
CVE-2022-32983MEDIUM5.3Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filter...
CVE-2022-2134MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.
CVE-2022-25772MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers ...
CVE-2022-1945MEDIUM4.8The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings...
CVE-2022-1915MEDIUM4.8The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use...
CVE-2022-1896MEDIUM4.8The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own...
CVE-2022-1895MEDIUM4.3The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction ...
CVE-2022-1889MEDIUM4.8The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow ...
CVE-2022-1832MEDIUM6.5The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co...
CVE-2022-1831MEDIUM6.5The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-1830MEDIUM6.5The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,...
CVE-2022-1829MEDIUM6.5The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which...
CVE-2022-1828MEDIUM6.5The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2022-1827MEDIUM6.5The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1826MEDIUM6.5The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou...
CVE-2022-1818MEDIUM5.4The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which ...
CVE-2022-1717MEDIUM4.8The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its sett...
CVE-2022-1630MEDIUM6.5The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now