2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26593 | MEDIUM | 5.4 | 0.6% | Apr 19, 2022 | Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through... |
| CVE-2022-0645 | MEDIUM | 6.1 | 0.8% | Apr 19, 2022 | Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to... |
| CVE-2022-24859 | MEDIUM | 5.5 | 1.3% | Apr 18, 2022 | PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF f... |
| CVE-2022-1112 | MEDIUM | 5.4 | 0.3% | Apr 18, 2022 | The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not ... |
| CVE-2022-1091 | MEDIUM | 6.1 | 1.2% | Apr 18, 2022 | The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the... |
| CVE-2022-1090 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high... |
| CVE-2022-1088 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which ... |
| CVE-2022-1063 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti... |
| CVE-2022-1054 | MEDIUM | 5.3 | 3.6% | Apr 18, 2022 | The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting... |
| CVE-2022-1001 | MEDIUM | 4.8 | 4.2% | Apr 18, 2022 | The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set... |
| CVE-2022-0994 | MEDIUM | 4.8 | 2.8% | Apr 18, 2022 | The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi... |
| CVE-2022-0879 | MEDIUM | 6.1 | 1.2% | Apr 18, 2022 | The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it b... |
| CVE-2022-0780 | MEDIUM | 6.1 | 0.8% | Apr 18, 2022 | The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti... |
| CVE-2022-0765 | MEDIUM | 5.4 | 4.0% | Apr 18, 2022 | The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source tran... |
| CVE-2022-0737 | MEDIUM | 4.8 | 0.8% | Apr 18, 2022 | The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil... |
| CVE-2022-0707 | MEDIUM | 4.3 | 0.5% | Apr 18, 2022 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes... |
| CVE-2022-0706 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the... |
| CVE-2022-27853 | MEDIUM | 4.8 | 0.5% | Apr 18, 2022 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.... |
| CVE-2022-27652 | MEDIUM | 5.3 | 0.2% | Apr 18, 2022 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability... |
| CVE-2022-23975 | MEDIUM | 6.5 | 0.5% | Apr 18, 2022 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any insta... |
| CVE-2022-28810 | MEDIUM | 6.8 | 70.4% | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary ... |
| CVE-2022-1383 | MEDIUM | 6.1 | 0.7% | Apr 18, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data ... |
| CVE-2022-1382 | MEDIUM | 5.5 | 0.7% | Apr 18, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making ... |
| CVE-2022-28966 | MEDIUM | 5.5 | 0.6% | Apr 16, 2022 | Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in ... |
| CVE-2022-26777 | MEDIUM | 5.3 | 2.0% | Apr 16, 2022 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now