2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-29417MEDIUM4.3Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a...
CVE-2022-28290MEDIUM6.1Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload execut...
CVE-2022-0477MEDIUM4.9An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting fr...
CVE-2022-27375MEDIUM6.5Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at ...
CVE-2022-27374MEDIUM6.5Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at ...
CVE-2022-26597MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7...
CVE-2022-26596MEDIUM6.1Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7....
CVE-2022-1396MEDIUM4.8The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i...
CVE-2022-1228MEDIUM4.8The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" ...
CVE-2022-1156MEDIUM4.8The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv...
CVE-2022-1153MEDIUM4.8The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v...
CVE-2022-1152MEDIUM5.4The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in ...
CVE-2022-1094MEDIUM4.8The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p...
CVE-2022-1092MEDIUM4.3The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export...
CVE-2022-1027MEDIUM4.8The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the...
CVE-2022-0953MEDIUM6.1The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER...
CVE-2022-0876MEDIUM4.8The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p...
CVE-2022-0634MEDIUM4.3The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, ...
CVE-2022-0398MEDIUM5.4The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks ...
CVE-2022-0363MEDIUM4.3The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-ex...
CVE-2022-0287MEDIUM4.3The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX...
CVE-2022-28094MEDIUM6.1SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability vi...
CVE-2022-28586MEDIUM6.1XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payloa...
CVE-2022-28506MEDIUM5.5There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
CVE-2022-27428MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now