2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3419MEDIUM6.5The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo...
CVE-2022-3408MEDIUM4.8The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3380HIGH7.2The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lea...
CVE-2022-3374HIGH7.2The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP obje...
CVE-2022-3366HIGH7.2The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2...
CVE-2022-3360HIGH8.1The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticat...
CVE-2022-3357HIGH8.8The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PH...
CVE-2022-3334HIGH7.2The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP obj...
CVE-2022-3254CRITICAL9.8The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor...
CVE-2022-3237MEDIUM4.8The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege u...
CVE-2022-3096MEDIUM5.4The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's setti...
CVE-2022-2627MEDIUM6.1The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via...
CVE-2022-2190MEDIUM6.1The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2022-2167MEDIUM6.1The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via...
CVE-2022-3772Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation d...
CVE-2022-3771CRITICAL9.8A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of...
CVE-2022-3770HIGH8.8A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in...
CVE-2022-40488MEDIUM6.5ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-40487MEDIUM6.1ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users ...
CVE-2022-37623CRITICAL9.8Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th...
CVE-2022-37620HIGH7.5A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnor...
CVE-2022-3766MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-3765MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-40742MEDIUM6.5Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vul...
CVE-2022-40741CRITICAL9.8Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now