2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0123 | MEDIUM | 6.8 | 0.4% | Mar 28, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an... |
| CVE-2022-0833 | MEDIUM | 4.3 | 0.5% | Mar 28, 2022 | The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as r... |
| CVE-2022-0818 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci... |
| CVE-2022-0720 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu... |
| CVE-2022-0680 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati... |
| CVE-2022-0647 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i... |
| CVE-2022-0643 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it b... |
| CVE-2022-0641 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting... |
| CVE-2022-0621 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an ad... |
| CVE-2022-0620 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it ... |
| CVE-2022-0619 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it bac... |
| CVE-2022-0600 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting ... |
| CVE-2022-0599 | MEDIUM | 6.1 | 1.7% | Mar 28, 2022 | The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id par... |
| CVE-2022-0595 | MEDIUM | 5.4 | 13.6% | Mar 28, 2022 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th... |
| CVE-2022-0493 | MEDIUM | 4.9 | 1.4% | Mar 28, 2022 | The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi... |
| CVE-2022-0450 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving me... |
| CVE-2022-0397 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter befo... |
| CVE-2022-0388 | MEDIUM | 4.8 | 0.6% | Mar 28, 2022 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, a... |
| CVE-2022-27950 | MEDIUM | 5.5 | 0.4% | Mar 28, 2022 | In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error conditio... |
| CVE-2022-26254 | MEDIUM | 5.3 | 0.8% | Mar 27, 2022 | WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows ... |
| CVE-2022-26252 | MEDIUM | 6.5 | 1.8% | Mar 27, 2022 | aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain th... |
| CVE-2022-27948 | MEDIUM | 4.3 | 1.4% | Mar 27, 2022 | Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a... |
| CVE-2022-27943 | MEDIUM | 5.5 | 0.9% | Mar 26, 2022 | libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new. |
| CVE-2022-27939 | MEDIUM | 5.5 | 1.0% | Mar 26, 2022 | tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. |
| CVE-2022-27938 | MEDIUM | 5.5 | 0.6% | Mar 26, 2022 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now