2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0901 | MEDIUM | 6.1 | 3.6% | Apr 4, 2022 | The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputtin... |
| CVE-2022-0884 | MEDIUM | 4.8 | 0.6% | Apr 4, 2022 | The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which... |
| CVE-2022-0864 | MEDIUM | 6.1 | 6.4% | Apr 4, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval... |
| CVE-2022-0837 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing ... |
| CVE-2022-0830 | MEDIUM | 6.5 | 0.5% | Apr 4, 2022 | The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting for... |
| CVE-2022-0825 | MEDIUM | 5.4 | 0.8% | Apr 4, 2022 | The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu... |
| CVE-2022-0431 | MEDIUM | 6.1 | 0.9% | Apr 4, 2022 | The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before ... |
| CVE-2022-0404 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me... |
| CVE-2022-28063 | MEDIUM | 4.9 | 1.1% | Apr 4, 2022 | Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products. |
| CVE-2022-27436 | MEDIUM | 4.8 | 1.0% | Apr 4, 2022 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attack... |
| CVE-2022-26616 | MEDIUM | 6.1 | 1.0% | Apr 4, 2022 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks... |
| CVE-2022-24191 | MEDIUM | 5.5 | 0.7% | Apr 4, 2022 | In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memo... |
| CVE-2022-1225 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6. |
| CVE-2022-1224 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. |
| CVE-2022-1223 | MEDIUM | 6.5 | 1.2% | Apr 4, 2022 | Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. |
| CVE-2022-1222 | MEDIUM | 5.5 | 0.8% | Apr 4, 2022 | Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-27248 | MEDIUM | 6.5 | 2.8% | Apr 3, 2022 | A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download ar... |
| CVE-2022-28389 | MEDIUM | 5.5 | 0.3% | Apr 3, 2022 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28388 | MEDIUM | 5.5 | 0.4% | Apr 3, 2022 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-0406 | MEDIUM | 4.3 | 0.7% | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. |
| CVE-2022-0405 | MEDIUM | 4.3 | 0.7% | Apr 3, 2022 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. |
| CVE-2022-28379 | MEDIUM | 4.8 | 71.2% | Apr 3, 2022 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. |
| CVE-2022-28378 | MEDIUM | 6.1 | 0.6% | Apr 3, 2022 | Craft CMS before 3.7.29 allows XSS. |
| CVE-2022-1211 | MEDIUM | 6.5 | 0.9% | Apr 3, 2022 | A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter... |
| CVE-2022-1210 | MEDIUM | 6.5 | 1.9% | Apr 3, 2022 | A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Ha... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now