2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0755MEDIUM4.3Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0754MEDIUM6.5SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
CVE-2022-0535MEDIUM4.8The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-0533MEDIUM6.1The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (X...
CVE-2022-0448MEDIUM4.8The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow h...
CVE-2022-0445MEDIUM6.5The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CS...
CVE-2022-0442MEDIUM4.3The UsersWP WordPress plugin before 1.2.3.1 is missing access controls when updating a user avatar, and does not make su...
CVE-2022-0429MEDIUM6.1The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable befor...
CVE-2022-0426MEDIUM5.4The Product Feed PRO for WooCommerce WordPress plugin before 11.2.3 does not escape the rowCount parameter before output...
CVE-2022-0422MEDIUM6.1The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter b...
CVE-2022-0389MEDIUM4.8The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high...
CVE-2022-0384MEDIUM4.3The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users A...
CVE-2022-0347MEDIUM6.1The LoginPress | Custom Login Page Customizer WordPress plugin before 1.5.12 does not escape the redirect-page parameter...
CVE-2022-0205MEDIUM5.4The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a ...
CVE-2022-0163MEDIUM6.5The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a...
CVE-2022-0697MEDIUM6.1Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
CVE-2022-0868MEDIUM6.1Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
CVE-2022-0869MEDIUM6.1Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
CVE-2022-0849MEDIUM5.5Use After Free in r_reg_get_name_idx in GitHub repository radareorg/radare2 prior to 5.6.6.
CVE-2022-25106MEDIUM5.5D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnera...
CVE-2022-26484MEDIUM4.9An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch...
CVE-2022-26483MEDIUM4.8An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch...
CVE-2022-0855MEDIUM6.1Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
CVE-2022-23232MEDIUM4.9StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when succe...
CVE-2022-26336MEDIUM5.5A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now