2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31041 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the for... |
| CVE-2022-2066 | MEDIUM | 6.1 | 0.9% | Jun 13, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06. |
| CVE-2022-2065 | MEDIUM | 5.4 | 0.6% | Jun 13, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06. |
| CVE-2022-1985 | MEDIUM | 6.1 | 1.1% | Jun 13, 2022 | The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and includi... |
| CVE-2022-1822 | MEDIUM | 6.1 | 1.0% | Jun 13, 2022 | The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parame... |
| CVE-2022-1814 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-1793 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a... |
| CVE-2022-1792 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-1790 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2022-1788 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks.... |
| CVE-2022-1787 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-1781 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2022-1780 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could ... |
| CVE-2022-1773 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an ad... |
| CVE-2022-1772 | MEDIUM | 4.8 | 0.7% | Jun 13, 2022 | The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re... |
| CVE-2022-1764 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2022-1763 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows c... |
| CVE-2022-1761 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This... |
| CVE-2022-1759 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic... |
| CVE-2022-1756 | MEDIUM | 6.1 | 1.8% | Jun 13, 2022 | The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it ... |
| CVE-2022-1724 | MEDIUM | 6.1 | 1.7% | Jun 13, 2022 | The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting t... |
| CVE-2022-1710 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel... |
| CVE-2022-1707 | MEDIUM | 6.1 | 88.6% | Jun 13, 2022 | The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s para... |
| CVE-2022-1694 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page... |
| CVE-2022-1656 | MEDIUM | 5.4 | 0.5% | Jun 13, 2022 | Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to acces... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now