2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1624MEDIUM6.5The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1612MEDIUM6.5The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c...
CVE-2022-1608MEDIUM6.5The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, ...
CVE-2022-1605MEDIUM6.5The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could...
CVE-2022-1604MEDIUM6.1The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2022-1595MEDIUM5.3The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque...
CVE-2022-1594MEDIUM4.3The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1549MEDIUM5.4The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor do...
CVE-2022-1532MEDIUM6.1Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at...
CVE-2022-1336MEDIUM4.8The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high...
CVE-2022-1335MEDIUM4.8The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig...
CVE-2022-1208MEDIUM5.4The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured o...
CVE-2022-0745MEDIUM6.5The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e...
CVE-2022-0626MEDIUM6.1The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting t...
CVE-2022-31040MEDIUM6.1Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie cons...
CVE-2022-2060MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-32741MEDIUM5.3Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based...
CVE-2022-32740MEDIUM5.3A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome...
CVE-2022-32739MEDIUM5.3When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received...
CVE-2022-29894MEDIUM4.8Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By explo...
CVE-2022-27231MEDIUM6.1Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl...
CVE-2022-27174MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthen...
CVE-2022-26041MEDIUM6.5Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrativ...
CVE-2022-31287MEDIUM5.5An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.
CVE-2022-31285MEDIUM5.5An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now