2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4174 | HIGH | 8.8 | 0.9% | Nov 30, 2022 | Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2022-46155 | MEDIUM | 6.4 | 0.4% | Nov 29, 2022 | Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script... |
| CVE-2022-4036 | MEDIUM | 5.3 | 0.4% | Nov 29, 2022 | The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.... |
| CVE-2022-4035 | MEDIUM | 6.1 | 0.7% | Nov 29, 2022 | The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field par... |
| CVE-2022-4034 | HIGH | 7.8 | 0.6% | Nov 29, 2022 | The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.7... |
| CVE-2022-4033 | MEDIUM | 5.3 | 0.7% | Nov 29, 2022 | The Quiz and Survey Master plugin for WordPress is vulnerable to input validation bypass via the 'question[id]' paramete... |
| CVE-2022-4032 | MEDIUM | 6.1 | 0.7% | Nov 29, 2022 | The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in ve... |
| CVE-2022-4031 | MEDIUM | 4.9 | 0.7% | Nov 29, 2022 | The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.... |
| CVE-2022-4030 | HIGH | 8.1 | 1.6% | Nov 29, 2022 | The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'fil... |
| CVE-2022-4029 | MEDIUM | 4.7 | 0.6% | Nov 29, 2022 | The Simple:Press plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sforum_[md5 hash of the W... |
| CVE-2022-4028 | MEDIUM | 5.4 | 0.5% | Nov 29, 2022 | The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula... |
| CVE-2022-4027 | MEDIUM | 5.4 | 0.6% | Nov 29, 2022 | The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula... |
| CVE-2022-3995 | MEDIUM | 4.3 | 0.6% | Nov 29, 2022 | The TeraWallet plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, ... |
| CVE-2022-3991 | MEDIUM | 5.4 | 0.6% | Nov 29, 2022 | The Photospace Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its settings parameters sav... |
| CVE-2022-3898 | MEDIUM | 6.5 | 0.4% | Nov 29, 2022 | The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ... |
| CVE-2022-3897 | MEDIUM | 4.8 | 0.5% | Nov 29, 2022 | The WP Affiliate Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ve... |
| CVE-2022-3896 | MEDIUM | 6.1 | 0.6% | Nov 29, 2022 | The WP Affiliate Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER["REQUEST_URI... |
| CVE-2022-3751 | CRITICAL | 9.8 | 0.9% | Nov 29, 2022 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. |
| CVE-2022-3747 | MEDIUM | 6.5 | 0.8% | Nov 29, 2022 | The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2.... |
| CVE-2022-3384 | HIGH | 7.2 | 2.7% | Nov 29, 2022 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 ... |
| CVE-2022-3383 | HIGH | 7.2 | 2.8% | Nov 29, 2022 | The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 ... |
| CVE-2022-3361 | MEDIUM | 4.3 | 2.5% | Nov 29, 2022 | The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due... |
| CVE-2022-36964 | HIGH | 8.8 | 16.8% | Nov 29, 2022 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa... |
| CVE-2022-36962 | HIGH | 7.2 | 9.0% | Nov 29, 2022 | SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete con... |
| CVE-2022-36960 | HIGH | 8.8 | 0.9% | Nov 29, 2022 | SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with vali... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now