2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22734MEDIUM6.1The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does n...
CVE-2022-0960MEDIUM5.4Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0703MEDIUM4.8The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege ...
CVE-2022-0702MEDIUM4.8The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such ...
CVE-2022-0701MEDIUM4.8The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high priv...
CVE-2022-0700MEDIUM4.8The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users...
CVE-2022-0684MEDIUM4.8The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege use...
CVE-2022-0674MEDIUM4.8The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high priv...
CVE-2022-0659MEDIUM4.8The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users su...
CVE-2022-0648MEDIUM6.1The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos par...
CVE-2022-0601MEDIUM6.1The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter be...
CVE-2022-0593MEDIUM6.5The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or a...
CVE-2022-0503MEDIUM6.1The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s paramete...
CVE-2022-0449MEDIUM6.1The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in so...
CVE-2022-0399MEDIUM6.1The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_s...
CVE-2022-0327MEDIUM6.1The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter b...
CVE-2022-0321MEDIUM6.1The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting i...
CVE-2022-0248MEDIUM6.1The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact for...
CVE-2022-0230MEDIUM6.1The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outpu...
CVE-2022-0165MEDIUM6.1The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u...
CVE-2022-0161MEDIUM6.1The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it...
CVE-2022-0147MEDIUM6.1The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outpu...
CVE-2022-24576MEDIUM5.5GPAC 1.0.1 is affected by Use After Free through MP4Box.
CVE-2022-24574MEDIUM5.5GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra ().
CVE-2022-0946MEDIUM5.4Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now