2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43352HIGH7.2Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php...
CVE-2022-43351MEDIUM6.5Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component...
CVE-2022-43350HIGH7.2Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php...
CVE-2022-43319HIGH7.5An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learnin...
CVE-2022-43318HIGH8.8Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit paramete...
CVE-2022-43317MEDIUM6.1A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attacke...
CVE-2022-43306HIGH8.8The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party...
CVE-2022-43305CRITICAL9.8The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part...
CVE-2022-43304CRITICAL9.8The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party...
CVE-2022-43303CRITICAL9.8The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par...
CVE-2022-38163LOW3.5A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below. ...
CVE-2022-37866HIGH7.5When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "...
CVE-2022-42956HIGH7.5The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
CVE-2022-42955HIGH7.5The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
CVE-2022-42920CRITICAL9.8Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However...
CVE-2022-2188MEDIUM5.5Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated priv...
CVE-2022-3873MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.
CVE-2022-37865CRITICAL9.1With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fl...
CVE-2022-3558HIGH8The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it...
CVE-2022-3537HIGH8.8The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks,...
CVE-2022-3536HIGH8.8The Role Based Pricing for WooCommerce WordPress plugin before 1.6.3 does not have authorisation and proper CSRF checks,...
CVE-2022-3494HIGH8.8The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to ...
CVE-2022-3489MEDIUM5.3The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom...
CVE-2022-3481CRITICAL9.8The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using ...
CVE-2022-3463CRITICAL9.8The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now