2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1303MEDIUM4.8The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h...
CVE-2022-1171MEDIUM6.1The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting ...
CVE-2022-1104MEDIUM4.8The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allo...
CVE-2022-1047MEDIUM6.1The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL b...
CVE-2022-0898MEDIUM5.4The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't hav...
CVE-2022-0874MEDIUM4.8The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us...
CVE-2022-0625MEDIUM6.1The Admin Menu Editor WordPress plugin through 1.0.4 does not sanitize and escape a parameter before outputting it back ...
CVE-2022-0424MEDIUM5.3The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX acti...
CVE-2022-30334MEDIUM5.3Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers....
CVE-2022-30330MEDIUM6.6In the KeepKey firmware before 7.3.2,Flaws in the supervisor interface can be exploited to bypass important security res...
CVE-2022-29422MEDIUM4.8Multiple Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerabilities in Adam Skaat's Countdown & Clock ...
CVE-2022-27909MEDIUM4.3In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see th...
CVE-2022-29421MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Adam Skaat's Countdown & Clock plugin on WordPress via &ycd_type v...
CVE-2022-29420MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Adam Skaat ...
CVE-2022-28545MEDIUM5.4FUDforum 3.1.1 is vulnerable to Stored XSS.
CVE-2022-28507MEDIUM4.8Dragon Path Technologies Bharti Airtel Routers Hardware BDT-121 version 1.0 is vulnerable to Cross Site Scripting (XSS) ...
CVE-2022-27183MEDIUM6.1The Monitoring Console app configured in Distributed mode allows for a Reflected XSS in a query parameter in Splunk Ente...
CVE-2022-26070MEDIUM4.3When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, ...
CVE-2022-28164MEDIUM6.5Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passw...
CVE-2022-24823MEDIUM5.5Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http...
CVE-2022-30295MEDIUM6.5uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache pois...
CVE-2022-24878MEDIUM6.5Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v...
CVE-2022-24902MEDIUM4.3TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideo...
CVE-2022-24899MEDIUM6.1Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In v...
CVE-2022-29172MEDIUM6.1Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Director...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now