2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0914MEDIUM6.5The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attac...
CVE-2022-0892MEDIUM6.1The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back ...
CVE-2022-0840MEDIUM4.8The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci...
CVE-2022-0728MEDIUM4.8The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow...
CVE-2022-0531MEDIUM6.1The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before...
CVE-2022-0471MEDIUM6.1The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result...
CVE-2022-0447MEDIUM6.4The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it ...
CVE-2022-0314MEDIUM6.1The Nimble Page Builder WordPress plugin before 3.2.2 does not sanitise and escape the preview-level-guid parameter befo...
CVE-2022-0271MEDIUM6.1The LearnPress WordPress plugin before 4.1.6 does not sanitise and escape the lp-dismiss-notice before outputting it bac...
CVE-2022-0246MEDIUM4.9The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio...
CVE-2022-26414MEDIUM5.5A potential buffer overflow vulnerability was identified in some internal functions of Zyxel VMG3312-T20A firmware versi...
CVE-2022-1045MEDIUM5.4Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
CVE-2022-0936MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository autolab/autolab prior to 2.8.0.
CVE-2022-27961MEDIUM5.4A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary ...
CVE-2022-27960MEDIUM5.4Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to a...
CVE-2022-27958MEDIUM5.4Insecure permissions configured in the userid parameter at /user/getuserprofile of FEBS-Security v1.0 allows attackers t...
CVE-2022-27476MEDIUM6.1A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbi...
CVE-2022-27280MEDIUM5.4InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a stored cross-site scr...
CVE-2022-27127MEDIUM6.5zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php.
CVE-2022-27125MEDIUM6.1zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /ph...
CVE-2022-1291MEDIUM5.4XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1...
CVE-2022-1290MEDIUM5.4Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers...
CVE-2022-1289MEDIUM6.5A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to...
CVE-2022-1288MEDIUM6.1A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue a...
CVE-2022-28365MEDIUM5.3Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminf...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now