2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1407 | MEDIUM | 6.5 | 0.5% | May 16, 2022 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a ... |
| CVE-2022-1398 | MEDIUM | 6.5 | 2.9% | May 16, 2022 | The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that... |
| CVE-2022-1393 | MEDIUM | 5.4 | 0.6% | May 16, 2022 | The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subti... |
| CVE-2022-1349 | MEDIUM | 4.3 | 0.6% | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid... |
| CVE-2022-1334 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which ... |
| CVE-2022-1267 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting i... |
| CVE-2022-1265 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which co... |
| CVE-2022-1217 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable befo... |
| CVE-2022-1216 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before ou... |
| CVE-2022-1089 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, whic... |
| CVE-2022-1062 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-1051 | MEDIUM | 5.4 | 1.2% | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanit... |
| CVE-2022-0873 | MEDIUM | 4.8 | 0.9% | May 16, 2022 | The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting ... |
| CVE-2022-0578 | MEDIUM | 6.5 | 0.8% | May 16, 2022 | Code Injection in GitHub repository publify/publify prior to 9.2.8. |
| CVE-2022-0574 | MEDIUM | 6.5 | 0.8% | May 16, 2022 | Improper Access Control in GitHub repository publify/publify prior to 9.2.8. |
| CVE-2022-30777 | MEDIUM | 6.1 | 2.1% | May 16, 2022 | Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. |
| CVE-2022-30776 | MEDIUM | 6.1 | 4.0% | May 16, 2022 | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. |
| CVE-2022-30013 | MEDIUM | 5.4 | 0.6% | May 16, 2022 | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execut... |
| CVE-2022-29017 | MEDIUM | 5.5 | 0.6% | May 16, 2022 | Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S. |
| CVE-2022-29587 | MEDIUM | 4 | 0.4% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka super... |
| CVE-2022-30775 | MEDIUM | 5.5 | 0.8% | May 16, 2022 | xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a... |
| CVE-2022-30770 | MEDIUM | 6.1 | 0.9% | May 16, 2022 | Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2... |
| CVE-2022-1702 | MEDIUM | 6.1 | 8.4% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifie... |
| CVE-2022-22393 | MEDIUM | 6.5 | 0.7% | May 13, 2022 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could ... |
| CVE-2022-22325 | MEDIUM | 5.5 | 0.2% | May 13, 2022 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now