2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0901MEDIUM6.1The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputtin...
CVE-2022-0884MEDIUM4.8The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which...
CVE-2022-0864MEDIUM6.1The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval...
CVE-2022-0837MEDIUM5.4The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing ...
CVE-2022-0830MEDIUM6.5The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting for...
CVE-2022-0825MEDIUM5.4The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu...
CVE-2022-0431MEDIUM6.1The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before ...
CVE-2022-0404MEDIUM6.5The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me...
CVE-2022-28063MEDIUM4.9Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
CVE-2022-27436MEDIUM4.8A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attack...
CVE-2022-26616MEDIUM6.1PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks...
CVE-2022-24191MEDIUM5.5In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memo...
CVE-2022-1225MEDIUM6.5Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
CVE-2022-1224MEDIUM6.5Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVE-2022-1223MEDIUM6.5Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
CVE-2022-1222MEDIUM5.5Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-27248MEDIUM6.5A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download ar...
CVE-2022-28389MEDIUM5.5mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
CVE-2022-28388MEDIUM5.5usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
CVE-2022-0406MEDIUM4.3Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-0405MEDIUM4.3Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
CVE-2022-28379MEDIUM4.8jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
CVE-2022-28378MEDIUM6.1Craft CMS before 3.7.29 allows XSS.
CVE-2022-1211MEDIUM6.5A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter...
CVE-2022-1210MEDIUM6.5A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Ha...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now