2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1645MEDIUM4.8The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-1644MEDIUM4.8The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a...
CVE-2022-1643MEDIUM4.8The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow ...
CVE-2022-1583MEDIUM6.5The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" w...
CVE-2022-1582MEDIUM6.1The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to...
CVE-2022-1568MEDIUM4.8The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile...
CVE-2022-1566MEDIUM4.8The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege use...
CVE-2022-1564MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou...
CVE-2022-1562MEDIUM5.4The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role a...
CVE-2022-1542MEDIUM4.8The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-1528MEDIUM6.1The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i...
CVE-2022-1527MEDIUM6.1The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin ...
CVE-2022-1456MEDIUM4.8The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privileg...
CVE-2022-1395MEDIUM4.8The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing ...
CVE-2022-1387MEDIUM4.8The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su...
CVE-2022-1299MEDIUM4.8The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which ...
CVE-2022-1294MEDIUM4.8The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high...
CVE-2022-1275MEDIUM4.8The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged...
CVE-2022-1203MEDIUM4.3The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as...
CVE-2022-1009MEDIUM6.1The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back...
CVE-2022-0642MEDIUM5.4The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugi...
CVE-2022-0376MEDIUM4.8The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels b...
CVE-2022-1928MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
CVE-2022-20807MEDIUM6.5Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc...
CVE-2022-20802MEDIUM5.4A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attac...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now