2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26593MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through...
CVE-2022-0645MEDIUM6.1Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to...
CVE-2022-24859MEDIUM5.5PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF f...
CVE-2022-1112MEDIUM5.4The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not ...
CVE-2022-1091MEDIUM6.1The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the...
CVE-2022-1090MEDIUM4.8The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high...
CVE-2022-1088MEDIUM4.8The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which ...
CVE-2022-1063MEDIUM4.8The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti...
CVE-2022-1054MEDIUM5.3The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting...
CVE-2022-1001MEDIUM4.8The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set...
CVE-2022-0994MEDIUM4.8The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi...
CVE-2022-0879MEDIUM6.1The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it b...
CVE-2022-0780MEDIUM6.1The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti...
CVE-2022-0765MEDIUM5.4The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source tran...
CVE-2022-0737MEDIUM4.8The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil...
CVE-2022-0707MEDIUM4.3The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes...
CVE-2022-0706MEDIUM4.8The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the...
CVE-2022-27853MEDIUM4.8Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0....
CVE-2022-27652MEDIUM5.3A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability...
CVE-2022-23975MEDIUM6.5Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any insta...
CVE-2022-28810MEDIUM6.8Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary ...
CVE-2022-1383MEDIUM6.1Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data ...
CVE-2022-1382MEDIUM5.5NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making ...
CVE-2022-28966MEDIUM5.5Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in ...
CVE-2022-26777MEDIUM5.3Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now