2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44167HIGH7.5Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.
CVE-2022-3861HIGH8.8The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des...
CVE-2022-3763HIGH8.1The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B...
CVE-2022-3762MEDIUM6.5The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, B...
CVE-2022-3753MEDIUM4.8The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-pri...
CVE-2022-3750MEDIUM4.7The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation.
CVE-2022-3720HIGH7.2The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL st...
CVE-2022-3691HIGH7.5The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL ...
CVE-2022-3690MEDIUM4.8The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allo...
CVE-2022-3688HIGH8.8The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could ...
CVE-2022-3634CRITICAL9.8The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV fi...
CVE-2022-3618MEDIUM4.8The Spacer WordPress plugin before 3.0.7 does not sanitize and escapes some of its settings, which could allow high-priv...
CVE-2022-3600CRITICAL9.8The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which c...
CVE-2022-3336MEDIUM4.3The Event Monster WordPress plugin before 1.2.0 does not have CSRF check when deleting visitors, which could allow attac...
CVE-2022-1581MEDIUM5.3The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO...
CVE-2022-1579HIGH7.5The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.
CVE-2022-1578HIGH8.8The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to ma...
CVE-2022-0421MEDIUM6.1The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation when changing whether a...
CVE-2022-45146MEDIUM5.5An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collecto...
CVE-2022-3589HIGH8.1An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low pri...
CVE-2022-4087MEDIUM4.3A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_...
CVE-2022-4093CRITICAL9.8SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or pe...
CVE-2022-4086Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-4085Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-4084Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now