2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0123MEDIUM6.8An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an...
CVE-2022-0833MEDIUM4.3The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as r...
CVE-2022-0818MEDIUM6.1The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci...
CVE-2022-0720MEDIUM5.4The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu...
CVE-2022-0680MEDIUM6.1The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati...
CVE-2022-0647MEDIUM6.1The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i...
CVE-2022-0643MEDIUM6.1The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it b...
CVE-2022-0641MEDIUM6.1The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting...
CVE-2022-0621MEDIUM6.1The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an ad...
CVE-2022-0620MEDIUM6.1The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it ...
CVE-2022-0619MEDIUM6.1The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it bac...
CVE-2022-0600MEDIUM6.1The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting ...
CVE-2022-0599MEDIUM6.1The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id par...
CVE-2022-0595MEDIUM5.4The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th...
CVE-2022-0493MEDIUM4.9The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi...
CVE-2022-0450MEDIUM5.4The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving me...
CVE-2022-0397MEDIUM5.4The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter befo...
CVE-2022-0388MEDIUM4.8The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, a...
CVE-2022-27950MEDIUM5.5In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error conditio...
CVE-2022-26254MEDIUM5.3WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows ...
CVE-2022-26252MEDIUM6.5aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain th...
CVE-2022-27948MEDIUM4.3Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a...
CVE-2022-27943MEDIUM5.5libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
CVE-2022-27939MEDIUM5.5tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
CVE-2022-27938MEDIUM5.5stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now