2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3900CRITICAL9.8The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before u...
CVE-2022-3883MEDIUM6.5The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 7.24 does not...
CVE-2022-3882MEDIUM6.5The Memory Usage, Memory Limit, PHP and Server Memory Health Check and Fix Plugin WordPress plugin before 2.46 does not ...
CVE-2022-3881MEDIUM5.7The WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Lo...
CVE-2022-3880MEDIUM6.5The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan WordPress plugin before 4...
CVE-2022-3879MEDIUM6.5The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authori...
CVE-2022-3862MEDIUM4.8The Livemesh Addons for Elementor WordPress plugin before 7.2.4 does not sanitise and escape some of its settings, which...
CVE-2022-3853MEDIUM5.4Cross-site Scripting (XSS) is a client-side code injection attack. The attacker aims to execute malicious scripts in a w...
CVE-2022-3609MEDIUM4.8The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow...
CVE-2022-3605HIGH7.8The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leadin...
CVE-2022-3359HIGH8.8The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported...
CVE-2022-45997HIGH7.2Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
CVE-2022-45996HIGH7.2Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
CVE-2022-45119Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-44147Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16891. Reason: This candidate is a reservation d...
CVE-2022-43503Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-45980HIGH8.8Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVE-2022-45979HIGH7.5Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wif...
CVE-2022-45977HIGH8.8Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
CVE-2022-45957HIGH7.5ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.
CVE-2022-45956MEDIUM5.3Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method...
CVE-2022-45043HIGH8.8Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
CVE-2022-4421MEDIUM6.1A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t...
CVE-2022-45970MEDIUM5.4Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.
CVE-2022-45968HIGH8.8Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (ev...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now