2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22734 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does n... |
| CVE-2022-0960 | MEDIUM | 5.4 | 0.8% | Mar 14, 2022 | Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0703 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege ... |
| CVE-2022-0702 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such ... |
| CVE-2022-0701 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high priv... |
| CVE-2022-0700 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users... |
| CVE-2022-0684 | MEDIUM | 4.8 | 0.7% | Mar 14, 2022 | The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege use... |
| CVE-2022-0674 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high priv... |
| CVE-2022-0659 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users su... |
| CVE-2022-0648 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the order_pos par... |
| CVE-2022-0601 | MEDIUM | 6.1 | 0.9% | Mar 14, 2022 | The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter be... |
| CVE-2022-0593 | MEDIUM | 6.5 | 1.4% | Mar 14, 2022 | The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or a... |
| CVE-2022-0503 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.2 does not sanitise and escape the s paramete... |
| CVE-2022-0449 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The Flexi WordPress plugin before 4.20 does not sanitise and escape various parameters before outputting them back in so... |
| CVE-2022-0399 | MEDIUM | 6.1 | 0.9% | Mar 14, 2022 | The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_s... |
| CVE-2022-0327 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The Master Addons for Elementor WordPress plugin before 1.8.5 does not sanitise and escape the error_message parameter b... |
| CVE-2022-0321 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting i... |
| CVE-2022-0248 | MEDIUM | 6.1 | 1.7% | Mar 14, 2022 | The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact for... |
| CVE-2022-0230 | MEDIUM | 6.1 | 1.5% | Mar 14, 2022 | The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outpu... |
| CVE-2022-0165 | MEDIUM | 6.1 | 4.3% | Mar 14, 2022 | The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the u... |
| CVE-2022-0161 | MEDIUM | 6.1 | 0.9% | Mar 14, 2022 | The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it... |
| CVE-2022-0147 | MEDIUM | 6.1 | 1.6% | Mar 14, 2022 | The Cookie Information | Free GDPR Consent Solution WordPress plugin before 2.0.8 does not escape user data before outpu... |
| CVE-2022-24576 | MEDIUM | 5.5 | 0.7% | Mar 14, 2022 | GPAC 1.0.1 is affected by Use After Free through MP4Box. |
| CVE-2022-24574 | MEDIUM | 5.5 | 0.7% | Mar 14, 2022 | GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra (). |
| CVE-2022-0946 | MEDIUM | 5.4 | 0.8% | Mar 14, 2022 | Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now