2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4312MEDIUM5.5 A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could all...
CVE-2022-4311MEDIUM6.5 An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This coul...
CVE-2022-4097MEDIUM5.3The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to by...
CVE-2022-4016MEDIUM6.5The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, B...
CVE-2022-4010MEDIUM4.8The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow...
CVE-2022-4005MEDIUM5.4The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow user...
CVE-2022-4004MEDIUM4.3The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donat...
CVE-2022-4000MEDIUM4.8The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could ...
CVE-2022-41881HIGH7.5Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackO...
CVE-2022-3999HIGH8.1The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which cou...
CVE-2022-3989HIGH8.8The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .ph...
CVE-2022-3982CRITICAL9.8The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which c...
CVE-2022-3981HIGH8.8The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a...
CVE-2022-3946MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing an...
CVE-2022-3935MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any...
CVE-2022-3934MEDIUM5.4The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pa...
CVE-2022-3933MEDIUM5.4The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow...
CVE-2022-3930MEDIUM6.5The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to chan...
CVE-2022-3925HIGH7.2The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL stateme...
CVE-2022-3921CRITICAL9.8The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthe...
CVE-2022-3919MEDIUM4.8The Jetpack CRM WordPress plugin before 5.4.3 does not sanitise and escape its settings, allowing high privilege users s...
CVE-2022-3915CRITICAL9.8The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL state...
CVE-2022-3912HIGH7.5The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX ac...
CVE-2022-3908MEDIUM6.1The Helloprint WordPress plugin before 1.4.7 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2022-3906MEDIUM4.8The Easy Form Builder WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, which could allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now