2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44167 | HIGH | 7.5 | 0.8% | Nov 21, 2022 | Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer. |
| CVE-2022-3861 | HIGH | 8.8 | 2.0% | Nov 21, 2022 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des... |
| CVE-2022-3763 | HIGH | 8.1 | 0.4% | Nov 21, 2022 | The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B... |
| CVE-2022-3762 | MEDIUM | 6.5 | 0.9% | Nov 21, 2022 | The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B... |
| CVE-2022-3753 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-pri... |
| CVE-2022-3750 | MEDIUM | 4.7 | 0.4% | Nov 21, 2022 | The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. |
| CVE-2022-3720 | HIGH | 7.2 | 1.0% | Nov 21, 2022 | The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL st... |
| CVE-2022-3691 | HIGH | 7.5 | 0.9% | Nov 21, 2022 | The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL ... |
| CVE-2022-3690 | MEDIUM | 4.8 | 0.6% | Nov 21, 2022 | The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allo... |
| CVE-2022-3688 | HIGH | 8.8 | 0.5% | Nov 21, 2022 | The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could ... |
| CVE-2022-3634 | CRITICAL | 9.8 | 3.6% | Nov 21, 2022 | The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV fi... |
| CVE-2022-3618 | MEDIUM | 4.8 | 0.5% | Nov 21, 2022 | The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-priv... |
| CVE-2022-3600 | CRITICAL | 9.8 | 1.2% | Nov 21, 2022 | The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which c... |
| CVE-2022-3336 | MEDIUM | 4.3 | 0.3% | Nov 21, 2022 | The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attac... |
| CVE-2022-1581 | MEDIUM | 5.3 | 0.6% | Nov 21, 2022 | The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO... |
| CVE-2022-1579 | HIGH | 7.5 | 0.7% | Nov 21, 2022 | The function check_is_login_page() uses headers for the IP check, which can be easily spoofed. |
| CVE-2022-1578 | HIGH | 8.8 | 0.4% | Nov 21, 2022 | The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to ma... |
| CVE-2022-0421 | MEDIUM | 6.1 | 0.5% | Nov 21, 2022 | The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a... |
| CVE-2022-45146 | MEDIUM | 5.5 | 0.4% | Nov 21, 2022 | An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collecto... |
| CVE-2022-3589 | HIGH | 8.1 | 0.7% | Nov 21, 2022 | An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low pri... |
| CVE-2022-4087 | MEDIUM | 4.3 | 0.5% | Nov 21, 2022 | A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_... |
| CVE-2022-4093 | CRITICAL | 9.8 | 4.0% | Nov 21, 2022 | SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or pe... |
| CVE-2022-4086 | — | — | — | Nov 20, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-4085 | — | — | — | Nov 20, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-4084 | — | — | — | Nov 20, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now