2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3847 | MEDIUM | 6.1 | 0.3% | Nov 28, 2022 | The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is mi... |
| CVE-2022-3839 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow... |
| CVE-2022-3834 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-3833 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, wh... |
| CVE-2022-3831 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2022-3828 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2022-3824 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could ... |
| CVE-2022-3823 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, whi... |
| CVE-2022-3822 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-3769 | HIGH | 8.8 | 1.1% | Nov 28, 2022 | The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2022-3768 | HIGH | 8.8 | 3.7% | Nov 28, 2022 | The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in... |
| CVE-2022-3689 | HIGH | 7.2 | 1.8% | Nov 28, 2022 | The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL sta... |
| CVE-2022-3610 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which coul... |
| CVE-2022-3603 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2... |
| CVE-2022-3601 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could... |
| CVE-2022-3511 | MEDIUM | 6.5 | 0.7% | Nov 28, 2022 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded bel... |
| CVE-2022-3490 | HIGH | 7.2 | 1.1% | Nov 28, 2022 | The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provi... |
| CVE-2022-2983 | MEDIUM | 4.8 | 0.5% | Nov 28, 2022 | The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users ... |
| CVE-2022-2311 | MEDIUM | 6.1 | 0.5% | Nov 28, 2022 | The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page ... |
| CVE-2022-4020 | HIGH | 8.2 | 0.2% | Nov 28, 2022 | Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated pr... |
| CVE-2022-38900 | HIGH | 7.5 | 24.9% | Nov 28, 2022 | decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS. |
| CVE-2022-36193 | CRITICAL | 9.8 | 1.4% | Nov 28, 2022 | SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang... |
| CVE-2022-43590 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback techn... |
| CVE-2022-43589 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Fi... |
| CVE-2022-43588 | MEDIUM | 5.5 | 0.3% | Nov 28, 2022 | A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Fi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now