2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1645 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2022-1644 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a... |
| CVE-2022-1643 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow ... |
| CVE-2022-1583 | MEDIUM | 6.5 | 1.3% | May 30, 2022 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" w... |
| CVE-2022-1582 | MEDIUM | 6.1 | 0.8% | May 30, 2022 | The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to... |
| CVE-2022-1568 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile... |
| CVE-2022-1566 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege use... |
| CVE-2022-1564 | MEDIUM | 4.8 | 1.0% | May 30, 2022 | The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou... |
| CVE-2022-1562 | MEDIUM | 5.4 | 0.6% | May 30, 2022 | The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role a... |
| CVE-2022-1542 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-1528 | MEDIUM | 6.1 | 0.8% | May 30, 2022 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i... |
| CVE-2022-1527 | MEDIUM | 6.1 | 0.8% | May 30, 2022 | The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin ... |
| CVE-2022-1456 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privileg... |
| CVE-2022-1395 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing ... |
| CVE-2022-1387 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su... |
| CVE-2022-1299 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which ... |
| CVE-2022-1294 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high... |
| CVE-2022-1275 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged... |
| CVE-2022-1203 | MEDIUM | 4.3 | 1.1% | May 30, 2022 | The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as... |
| CVE-2022-1009 | MEDIUM | 6.1 | 0.8% | May 30, 2022 | The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back... |
| CVE-2022-0642 | MEDIUM | 5.4 | 0.3% | May 30, 2022 | The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugi... |
| CVE-2022-0376 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels b... |
| CVE-2022-1928 | MEDIUM | 5.4 | 0.8% | May 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. |
| CVE-2022-20807 | MEDIUM | 6.5 | 0.9% | May 27, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc... |
| CVE-2022-20802 | MEDIUM | 5.4 | 0.6% | May 27, 2022 | A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attac... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now