2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1712 | MEDIUM | 4.3 | 0.4% | Jun 8, 2022 | The LiveSync for WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could ... |
| CVE-2022-1709 | MEDIUM | 4.3 | 0.4% | Jun 8, 2022 | The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all... |
| CVE-2022-1695 | MEDIUM | 4.3 | 0.4% | Jun 8, 2022 | The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, a... |
| CVE-2022-1691 | MEDIUM | 4.9 | 1.0% | Jun 8, 2022 | The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using... |
| CVE-2022-1685 | MEDIUM | 4.9 | 1.0% | Jun 8, 2022 | The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef... |
| CVE-2022-1673 | MEDIUM | 6.1 | 0.8% | Jun 8, 2022 | The WooCommerce Green Wallet Gateway WordPress plugin before 1.0.2 does not escape the error_envision query parameter be... |
| CVE-2022-1647 | MEDIUM | 4.8 | 0.6% | Jun 8, 2022 | The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users suc... |
| CVE-2022-1598 | MEDIUM | 5.3 | 5.6% | Jun 8, 2022 | The WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a RES... |
| CVE-2022-1597 | MEDIUM | 6.1 | 2.9% | Jun 8, 2022 | The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape... |
| CVE-2022-1577 | MEDIUM | 5.4 | 0.4% | Jun 8, 2022 | The Database Backup for WordPress plugin before 2.5.2 does not have CSRF check in place when updating the schedule backu... |
| CVE-2022-1570 | MEDIUM | 6.5 | 0.4% | Jun 8, 2022 | The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its set... |
| CVE-2022-1569 | MEDIUM | 4.8 | 0.6% | Jun 8, 2022 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Wor... |
| CVE-2022-1541 | MEDIUM | 4.8 | 0.6% | Jun 8, 2022 | The Video Slider WordPress plugin before 1.4.8 does not sanitize or escape some of its video settings, which could allow... |
| CVE-2022-1506 | MEDIUM | 5.4 | 0.6% | Jun 8, 2022 | The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields, which could allow users... |
| CVE-2022-1469 | MEDIUM | 4.8 | 0.6% | Jun 8, 2022 | The FiboSearch WordPress plugin before 1.17.0 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2022-1424 | MEDIUM | 6.5 | 0.5% | Jun 8, 2022 | The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker t... |
| CVE-2022-1422 | MEDIUM | 6.5 | 0.5% | Jun 8, 2022 | The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an ... |
| CVE-2022-1421 | MEDIUM | 4.3 | 1.2% | Jun 8, 2022 | The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in ad... |
| CVE-2022-1394 | MEDIUM | 4.8 | 1.0% | Jun 8, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.6.4 does not properly validate and escape some of its settings, whi... |
| CVE-2022-1241 | MEDIUM | 6.1 | 0.8% | Jun 8, 2022 | The Ask me WordPress theme before 6.8.2 does not properly sanitise and escape several of the fields in the Edit Profile ... |
| CVE-2022-1005 | MEDIUM | 6.1 | 0.9% | Jun 8, 2022 | The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back i... |
| CVE-2022-0779 | MEDIUM | 6.5 | 2.2% | Jun 8, 2022 | The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX a... |
| CVE-2022-31470 | MEDIUM | 6.1 | 52.1% | Jun 7, 2022 | An XSS vulnerability in the index_mobile_changepass.hsp reset-password section of Axigen Mobile WebMail before 10.2.3.12... |
| CVE-2022-30466 | MEDIUM | 6.5 | 0.7% | Jun 7, 2022 | joyebike Joy ebike Wolf Manufacturing year 2022 is vulnerable to Authentication Bypass by Capture-replay. |
| CVE-2022-29620 | MEDIUM | 6.5 | 1.7% | Jun 7, 2022 | FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOT... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now