2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43492 | HIGH | 8.8 | 0.6% | Nov 18, 2022 | Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPr... |
| CVE-2022-42883 | HIGH | 7.5 | 0.7% | Nov 18, 2022 | Sensitive Information Disclosure vulnerability discovered by Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2022-42698 | CRITICAL | 9.8 | 0.9% | Nov 18, 2022 | Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress. |
| CVE-2022-42497 | CRITICAL | 9.8 | 1.1% | Nov 18, 2022 | Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress. |
| CVE-2022-42459 | HIGH | 7.2 | 0.8% | Nov 18, 2022 | Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress. |
| CVE-2022-41839 | MEDIUM | 5.3 | 0.5% | Nov 18, 2022 | Broken Access Control vulnerability in WordPress LoginPress plugin <= 1.6.2 on WordPress leading to unauth. changing of ... |
| CVE-2022-41788 | MEDIUM | 5.4 | 0.4% | Nov 18, 2022 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Soledad premium theme <= 8.2.5 on WordPress. |
| CVE-2022-41685 | HIGH | 8.8 | 0.4% | Nov 18, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Viszt Péter's Integration for Szamlazz.hu & WooCommerce pl... |
| CVE-2022-41655 | MEDIUM | 6.5 | 0.6% | Nov 18, 2022 | Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress. |
| CVE-2022-41643 | MEDIUM | 4.8 | 0.4% | Nov 18, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Accessibility plugin <= 1.0.3 on WordPress. |
| CVE-2022-41634 | HIGH | 8.8 | 0.3% | Nov 18, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Media Library Folders plugin <= 7.1.1 on WordPress. |
| CVE-2022-41618 | MEDIUM | 5.3 | 0.5% | Nov 18, 2022 | Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress. |
| CVE-2022-41615 | MEDIUM | 6.1 | 0.2% | Nov 18, 2022 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordP... |
| CVE-2022-41135 | MEDIUM | 5.3 | 0.5% | Nov 18, 2022 | Unauth. Plugin Settings Change vulnerability in Modula plugin <= 2.6.9 on WordPress. |
| CVE-2022-40963 | MEDIUM | 5.4 | 0.4% | Nov 18, 2022 | Multiple Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerabilities in WP Page Builder plugin <= 1.2.6 on WordPre... |
| CVE-2022-40698 | MEDIUM | 6.1 | 0.4% | Nov 18, 2022 | Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Quiz And Survey Master plugin <= 7.3.10 on WordPress. |
| CVE-2022-40695 | HIGH | 8.8 | 0.3% | Nov 18, 2022 | Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress. |
| CVE-2022-40216 | MEDIUM | 6.5 | 0.4% | Nov 18, 2022 | Auth. (subscriber+) Messaging Block Bypass vulnerability in Better Messages plugin <= 1.9.10.69 on WordPress. |
| CVE-2022-40130 | LOW | 3.1 | 0.4% | Nov 18, 2022 | Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress. |
| CVE-2022-38871 | HIGH | 7.5 | 0.7% | Nov 18, 2022 | In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages. |
| CVE-2022-34827 | CRITICAL | 9.9 | 0.8% | Nov 18, 2022 | Carel Boss Mini 1.5.0 has Improper Access Control. |
| CVE-2022-31694 | HIGH | 7.3 | 0.2% | Nov 18, 2022 | InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent dir... |
| CVE-2022-41911 | HIGH | 7.5 | 0.4% | Nov 18, 2022 | TensorFlow is an open source platform for machine learning. When printing a tensor, we get it's data as a `const char*` ... |
| CVE-2022-41909 | HIGH | 7.5 | 0.5% | Nov 18, 2022 | TensorFlow is an open source platform for machine learning. An input `encoded` that is not a valid `CompositeTensorVaria... |
| CVE-2022-41908 | HIGH | 7.5 | 0.4% | Nov 18, 2022 | TensorFlow is an open source platform for machine learning. An input `token` that is not a UTF-8 bytestring will trigger... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now