2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0914 | MEDIUM | 6.5 | 0.6% | Apr 11, 2022 | The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attac... |
| CVE-2022-0892 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back ... |
| CVE-2022-0840 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci... |
| CVE-2022-0728 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow... |
| CVE-2022-0531 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before... |
| CVE-2022-0471 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result... |
| CVE-2022-0447 | MEDIUM | 6.4 | 0.6% | Apr 11, 2022 | The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it ... |
| CVE-2022-0314 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo... |
| CVE-2022-0271 | MEDIUM | 6.1 | 2.2% | Apr 11, 2022 | The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac... |
| CVE-2022-0246 | MEDIUM | 4.9 | 3.4% | Apr 11, 2022 | The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio... |
| CVE-2022-26414 | MEDIUM | 5.5 | 0.2% | Apr 11, 2022 | A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware versi... |
| CVE-2022-1045 | MEDIUM | 5.4 | 1.5% | Apr 11, 2022 | Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0. |
| CVE-2022-0936 | MEDIUM | 5.4 | 0.6% | Apr 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0. |
| CVE-2022-27961 | MEDIUM | 5.4 | 0.4% | Apr 10, 2022 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary ... |
| CVE-2022-27960 | MEDIUM | 5.4 | 0.4% | Apr 10, 2022 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to a... |
| CVE-2022-27958 | MEDIUM | 5.4 | 0.6% | Apr 10, 2022 | Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers t... |
| CVE-2022-27476 | MEDIUM | 6.1 | 0.5% | Apr 10, 2022 | A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbi... |
| CVE-2022-27280 | MEDIUM | 5.4 | 0.5% | Apr 10, 2022 | InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scr... |
| CVE-2022-27127 | MEDIUM | 6.5 | 0.6% | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php. |
| CVE-2022-27125 | MEDIUM | 6.1 | 0.6% | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /ph... |
| CVE-2022-1291 | MEDIUM | 5.4 | 0.7% | Apr 10, 2022 | XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1... |
| CVE-2022-1290 | MEDIUM | 5.4 | 1.6% | Apr 10, 2022 | Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers... |
| CVE-2022-1289 | MEDIUM | 6.5 | 1.1% | Apr 10, 2022 | A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to... |
| CVE-2022-1288 | MEDIUM | 6.1 | 0.5% | Apr 9, 2022 | A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue a... |
| CVE-2022-28365 | MEDIUM | 5.3 | 8.0% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminf... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now