2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4174HIGH8.8Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corru...
CVE-2022-46155MEDIUM6.4Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script...
CVE-2022-4036MEDIUM5.3The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3....
CVE-2022-4035MEDIUM6.1The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field par...
CVE-2022-4034HIGH7.8The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.7...
CVE-2022-4033MEDIUM5.3The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' paramete...
CVE-2022-4032MEDIUM6.1The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in ve...
CVE-2022-4031MEDIUM4.9The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6....
CVE-2022-4030HIGH8.1The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'fil...
CVE-2022-4029MEDIUM4.7The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the W...
CVE-2022-4028MEDIUM5.4The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula...
CVE-2022-4027MEDIUM5.4The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula...
CVE-2022-3995MEDIUM4.3The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, ...
CVE-2022-3991MEDIUM5.4The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters sav...
CVE-2022-3898MEDIUM6.5The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ...
CVE-2022-3897MEDIUM4.8The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve...
CVE-2022-3896MEDIUM6.1The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI...
CVE-2022-3751CRITICAL9.8SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
CVE-2022-3747MEDIUM6.5The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2....
CVE-2022-3384HIGH7.2The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 ...
CVE-2022-3383HIGH7.2The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 ...
CVE-2022-3361MEDIUM4.3The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due...
CVE-2022-36964HIGH8.8SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-36962HIGH7.2SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete con...
CVE-2022-36960HIGH8.8SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with vali...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now