2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1624 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1612 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-1608 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, ... |
| CVE-2022-1605 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could... |
| CVE-2022-1604 | MEDIUM | 6.1 | 0.8% | Jun 13, 2022 | The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2022-1595 | MEDIUM | 5.3 | 2.6% | Jun 13, 2022 | The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque... |
| CVE-2022-1594 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1549 | MEDIUM | 5.4 | 0.6% | Jun 13, 2022 | The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor do... |
| CVE-2022-1532 | MEDIUM | 6.1 | 0.8% | Jun 13, 2022 | Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at... |
| CVE-2022-1336 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high... |
| CVE-2022-1335 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig... |
| CVE-2022-1208 | MEDIUM | 5.4 | 0.9% | Jun 13, 2022 | The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured o... |
| CVE-2022-0745 | MEDIUM | 6.5 | 0.8% | Jun 13, 2022 | The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e... |
| CVE-2022-0626 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting t... |
| CVE-2022-31040 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie cons... |
| CVE-2022-2060 | MEDIUM | 5.4 | 0.8% | Jun 13, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0. |
| CVE-2022-32741 | MEDIUM | 5.3 | 0.8% | Jun 13, 2022 | Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based... |
| CVE-2022-32740 | MEDIUM | 5.3 | 0.7% | Jun 13, 2022 | A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome... |
| CVE-2022-32739 | MEDIUM | 5.3 | 0.7% | Jun 13, 2022 | When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received... |
| CVE-2022-29894 | MEDIUM | 4.8 | 0.7% | Jun 13, 2022 | Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By explo... |
| CVE-2022-27231 | MEDIUM | 6.1 | 1.0% | Jun 13, 2022 | Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl... |
| CVE-2022-27174 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthen... |
| CVE-2022-26041 | MEDIUM | 6.5 | 1.4% | Jun 13, 2022 | Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrativ... |
| CVE-2022-31287 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp. |
| CVE-2022-31285 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now