2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3419 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allo... |
| CVE-2022-3408 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The WP Word Count WordPress plugin through 3.2.3 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-3380 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lea... |
| CVE-2022-3374 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP obje... |
| CVE-2022-3366 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2... |
| CVE-2022-3360 | HIGH | 8.1 | 1.8% | Oct 31, 2022 | The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticat... |
| CVE-2022-3357 | HIGH | 8.8 | 1.9% | Oct 31, 2022 | The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PH... |
| CVE-2022-3334 | HIGH | 7.2 | 1.1% | Oct 31, 2022 | The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP obj... |
| CVE-2022-3254 | CRITICAL | 9.8 | 5.1% | Oct 31, 2022 | The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor... |
| CVE-2022-3237 | MEDIUM | 4.8 | 0.5% | Oct 31, 2022 | The WP Contact Slider WordPress plugin before 2.4.8 does not sanitize and escape its settings, allowing high privilege u... |
| CVE-2022-3096 | MEDIUM | 5.4 | 0.4% | Oct 31, 2022 | The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's setti... |
| CVE-2022-2627 | MEDIUM | 6.1 | 1.0% | Oct 31, 2022 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via... |
| CVE-2022-2190 | MEDIUM | 6.1 | 0.6% | Oct 31, 2022 | The Gallery Plugin for WordPress plugin before 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outp... |
| CVE-2022-2167 | MEDIUM | 6.1 | 0.6% | Oct 31, 2022 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via... |
| CVE-2022-3772 | — | — | — | Oct 31, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation d... |
| CVE-2022-3771 | CRITICAL | 9.8 | 0.5% | Oct 31, 2022 | A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of... |
| CVE-2022-3770 | HIGH | 8.8 | 0.5% | Oct 31, 2022 | A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in... |
| CVE-2022-40488 | MEDIUM | 6.5 | 0.3% | Oct 31, 2022 | ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). |
| CVE-2022-40487 | MEDIUM | 6.1 | 0.4% | Oct 31, 2022 | ProcessWire v3.0.200 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Search Users ... |
| CVE-2022-37623 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
| CVE-2022-37620 | HIGH | 7.5 | 1.1% | Oct 31, 2022 | A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnor... |
| CVE-2022-3766 | MEDIUM | 6.1 | 5.7% | Oct 31, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-3765 | MEDIUM | 5.4 | 0.5% | Oct 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.8. |
| CVE-2022-40742 | MEDIUM | 6.5 | 0.6% | Oct 31, 2022 | Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vul... |
| CVE-2022-40741 | CRITICAL | 9.8 | 1.1% | Oct 31, 2022 | Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacke... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now