2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1303 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h... |
| CVE-2022-1171 | MEDIUM | 6.1 | 0.8% | May 9, 2022 | The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting ... |
| CVE-2022-1104 | MEDIUM | 4.8 | 53.9% | May 9, 2022 | The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allo... |
| CVE-2022-1047 | MEDIUM | 6.1 | 0.8% | May 9, 2022 | The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL b... |
| CVE-2022-0898 | MEDIUM | 5.4 | 0.6% | May 9, 2022 | The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't hav... |
| CVE-2022-0874 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us... |
| CVE-2022-0625 | MEDIUM | 6.1 | 0.8% | May 9, 2022 | The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back ... |
| CVE-2022-0424 | MEDIUM | 5.3 | 2.7% | May 9, 2022 | The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX acti... |
| CVE-2022-30334 | MEDIUM | 5.3 | 2.2% | May 7, 2022 | Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers.... |
| CVE-2022-30330 | MEDIUM | 6.6 | 0.5% | May 7, 2022 | In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security res... |
| CVE-2022-29422 | MEDIUM | 4.8 | 0.5% | May 6, 2022 | Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock ... |
| CVE-2022-27909 | MEDIUM | 4.3 | 0.8% | May 6, 2022 | In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see th... |
| CVE-2022-29421 | MEDIUM | 6.1 | 0.7% | May 6, 2022 | Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type v... |
| CVE-2022-29420 | MEDIUM | 4.8 | 0.4% | May 6, 2022 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat ... |
| CVE-2022-28545 | MEDIUM | 5.4 | 0.4% | May 6, 2022 | FUDforum 3.1.1 is vulnerable to Stored XSS. |
| CVE-2022-28507 | MEDIUM | 4.8 | 0.5% | May 6, 2022 | Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS) ... |
| CVE-2022-27183 | MEDIUM | 6.1 | 0.6% | May 6, 2022 | The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Ente... |
| CVE-2022-26070 | MEDIUM | 4.3 | 0.6% | May 6, 2022 | When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, ... |
| CVE-2022-28164 | MEDIUM | 6.5 | 0.3% | May 6, 2022 | Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passw... |
| CVE-2022-24823 | MEDIUM | 5.5 | 1.0% | May 6, 2022 | Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http... |
| CVE-2022-30295 | MEDIUM | 6.5 | 11.3% | May 6, 2022 | uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache pois... |
| CVE-2022-24878 | MEDIUM | 6.5 | 0.9% | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v... |
| CVE-2022-24902 | MEDIUM | 4.3 | 0.5% | May 6, 2022 | TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideo... |
| CVE-2022-24899 | MEDIUM | 6.1 | 3.7% | May 6, 2022 | Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In v... |
| CVE-2022-29172 | MEDIUM | 6.1 | 0.6% | May 5, 2022 | Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Director... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now