2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29417 | MEDIUM | 4.3 | 0.6% | Apr 25, 2022 | Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a... |
| CVE-2022-28290 | MEDIUM | 6.1 | 1.4% | Apr 25, 2022 | Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload execut... |
| CVE-2022-0477 | MEDIUM | 4.9 | 0.9% | Apr 25, 2022 | An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting fr... |
| CVE-2022-27375 | MEDIUM | 6.5 | 0.4% | Apr 25, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at ... |
| CVE-2022-27374 | MEDIUM | 6.5 | 0.4% | Apr 25, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at ... |
| CVE-2022-26597 | MEDIUM | 6.1 | 0.7% | Apr 25, 2022 | Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7... |
| CVE-2022-26596 | MEDIUM | 6.1 | 0.7% | Apr 25, 2022 | Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.... |
| CVE-2022-1396 | MEDIUM | 4.8 | 1.0% | Apr 25, 2022 | The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i... |
| CVE-2022-1228 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" ... |
| CVE-2022-1156 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv... |
| CVE-2022-1153 | MEDIUM | 4.8 | 2.7% | Apr 25, 2022 | The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v... |
| CVE-2022-1152 | MEDIUM | 5.4 | 0.6% | Apr 25, 2022 | The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in ... |
| CVE-2022-1094 | MEDIUM | 4.8 | 0.7% | Apr 25, 2022 | The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2022-1092 | MEDIUM | 4.3 | 0.4% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export... |
| CVE-2022-1027 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the... |
| CVE-2022-0953 | MEDIUM | 6.1 | 2.7% | Apr 25, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER... |
| CVE-2022-0876 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p... |
| CVE-2022-0634 | MEDIUM | 4.3 | 0.3% | Apr 25, 2022 | The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, ... |
| CVE-2022-0398 | MEDIUM | 5.4 | 0.3% | Apr 25, 2022 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks ... |
| CVE-2022-0363 | MEDIUM | 4.3 | 0.3% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-ex... |
| CVE-2022-0287 | MEDIUM | 4.3 | 0.8% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX... |
| CVE-2022-28094 | MEDIUM | 6.1 | 0.9% | Apr 25, 2022 | SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability vi... |
| CVE-2022-28586 | MEDIUM | 6.1 | 0.6% | Apr 25, 2022 | XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payloa... |
| CVE-2022-28506 | MEDIUM | 5.5 | 1.2% | Apr 25, 2022 | There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45. |
| CVE-2022-27428 | MEDIUM | 5.4 | 0.5% | Apr 25, 2022 | A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now