2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3900 | CRITICAL | 9.8 | 19.0% | Dec 12, 2022 | The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before u... |
| CVE-2022-3883 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not... |
| CVE-2022-3882 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not ... |
| CVE-2022-3881 | MEDIUM | 5.7 | 0.4% | Dec 12, 2022 | The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Lo... |
| CVE-2022-3880 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4... |
| CVE-2022-3879 | MEDIUM | 6.5 | 0.3% | Dec 12, 2022 | The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authori... |
| CVE-2022-3862 | MEDIUM | 4.8 | 0.5% | Dec 12, 2022 | The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which... |
| CVE-2022-3853 | MEDIUM | 5.4 | 0.2% | Dec 12, 2022 | Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a w... |
| CVE-2022-3609 | MEDIUM | 4.8 | 0.4% | Dec 12, 2022 | The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow... |
| CVE-2022-3605 | HIGH | 7.8 | 0.4% | Dec 12, 2022 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leadin... |
| CVE-2022-3359 | HIGH | 8.8 | 0.7% | Dec 12, 2022 | The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported... |
| CVE-2022-45997 | HIGH | 7.2 | 0.9% | Dec 12, 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow. |
| CVE-2022-45996 | HIGH | 7.2 | 2.3% | Dec 12, 2022 | Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output. |
| CVE-2022-45119 | — | — | — | Dec 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-44147 | — | — | — | Dec 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16891. Reason: This candidate is a reservation d... |
| CVE-2022-43503 | — | — | — | Dec 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-45980 | HIGH | 8.8 | 7.5% | Dec 12, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet . |
| CVE-2022-45979 | HIGH | 7.5 | 0.8% | Dec 12, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wif... |
| CVE-2022-45977 | HIGH | 8.8 | 2.1% | Dec 12, 2022 | Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function. |
| CVE-2022-45957 | HIGH | 7.5 | 11.5% | Dec 12, 2022 | ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow. |
| CVE-2022-45956 | MEDIUM | 5.3 | 0.8% | Dec 12, 2022 | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method... |
| CVE-2022-45043 | HIGH | 8.8 | 2.2% | Dec 12, 2022 | Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set. |
| CVE-2022-4421 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t... |
| CVE-2022-45970 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board. |
| CVE-2022-45968 | HIGH | 8.8 | 1.0% | Dec 12, 2022 | Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (ev... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now