2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3847MEDIUM6.1The Showing URL in QR Code WordPress plugin through 0.0.1 does not have CSRF check when updating its settings, and is mi...
CVE-2022-3839MEDIUM4.8The Analytics for WP WordPress plugin through 1.5.1 does not sanitise and escape some of its settings, which could allow...
CVE-2022-3834MEDIUM4.8The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-3833MEDIUM4.8The Fancier Author Box by ThematoSoup WordPress plugin through 1.4 does not sanitise and escape some of its settings, wh...
CVE-2022-3831MEDIUM4.8The reCAPTCHA WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-3828MEDIUM4.8The Video Thumbnails WordPress plugin through 2.12.3 does not sanitise and escape some of its settings, which could allo...
CVE-2022-3824MEDIUM4.8The WP Admin UI Customize WordPress plugin before 1.5.13 does not sanitise and escape some of its settings, which could ...
CVE-2022-3823MEDIUM4.8The Beautiful Cookie Consent Banner WordPress plugin before 2.9.1 does not sanitise and escape some of its settings, whi...
CVE-2022-3822MEDIUM4.8The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could al...
CVE-2022-3769HIGH8.8The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-3768HIGH8.8The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in...
CVE-2022-3689HIGH7.2The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL sta...
CVE-2022-3610MEDIUM4.8The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which coul...
CVE-2022-3603CRITICAL9.8The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2...
CVE-2022-3601MEDIUM4.8The Image Hover Effects Css3 WordPress plugin through 4.5 does not sanitise and escape some of its settings, which could...
CVE-2022-3511MEDIUM6.5The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded bel...
CVE-2022-3490HIGH7.2The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provi...
CVE-2022-2983MEDIUM4.8The Salat Times WordPress plugin before 3.2.2 does not sanitize and escapes its settings, allowing high-privilege users ...
CVE-2022-2311MEDIUM6.1The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page ...
CVE-2022-4020HIGH8.2Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated pr...
CVE-2022-38900HIGH7.5decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
CVE-2022-36193CRITICAL9.8SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang...
CVE-2022-43590MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback techn...
CVE-2022-43589MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Fi...
CVE-2022-43588MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Fi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now