2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24187HIGH7.5The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object...
CVE-2022-46147MEDIUM6.1Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target...
CVE-2022-45921HIGH7.5FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. ...
CVE-2022-45442HIGH8.8Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 befo...
CVE-2022-44937MEDIUM6.5Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrato...
CVE-2022-41965MEDIUM6.1Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Open...
CVE-2022-38140HIGH8.8Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
CVE-2022-34654HIGH8.8Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.
CVE-2022-4104MEDIUM5.5A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compressio...
CVE-2022-4169MEDIUM5.3The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3....
CVE-2022-41732MEDIUM5.5 IBM Maximo Mobile 8.7 and 8.8 stores user credentials in plain clear text which can be read by a local user. IBM X-Forc...
CVE-2022-44399CRITICAL9.8Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/c...
CVE-2022-44401CRITICAL9.8Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
CVE-2022-44400CRITICAL9.8Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
CVE-2022-44284MEDIUM5.4Dinstar FXO Analog VoIP Gateway DAG2000-16O is vulnerable to Cross Site Scripting (XSS).
CVE-2022-44283CRITICAL9.8AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.
CVE-2022-41957HIGH7.5Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara...
CVE-2022-41944MEDIUM4.3Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions pr...
CVE-2022-41921MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlim...
CVE-2022-41912CRITICAL9.8The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML respon...
CVE-2022-31877HIGH8.8An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a c...
CVE-2022-3865HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2022-3850MEDIUM4.3The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow a...
CVE-2022-3849HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2022-3848HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now