2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42890HIGH7.5A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. T...
CVE-2022-41704HIGH7.5A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue af...
CVE-2022-3395HIGH8.8The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a databas...
CVE-2022-3394HIGH7.2The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with ...
CVE-2022-3393CRITICAL9.8The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV...
CVE-2022-3392MEDIUM4.8The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3391MEDIUM4.8The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-3350MEDIUM4.8The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could all...
CVE-2022-3344MEDIUM5.5A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept th...
CVE-2022-3335HIGH7.2The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which...
CVE-2022-3302HIGH7.2The Spam protection, AntiSpam, FireWall by CleanTalk WordPress plugin before 5.185.1 does not validate ids before using ...
CVE-2022-3300HIGH7.2The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it...
CVE-2022-3247MEDIUM6.5The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJA...
CVE-2022-3246HIGH8.8The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not properly sanitise and escape...
CVE-2022-3097MEDIUM6.5The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible f...
CVE-2022-39837MEDIUM5.5An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi...
CVE-2022-39836MEDIUM5.5An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi...
CVE-2022-39351MEDIUM4.4Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software ...
CVE-2022-39350MEDIUM5.4@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis...
CVE-2022-39349MEDIUM5.5The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `Shar...
CVE-2022-39345HIGH7.5Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac...
CVE-2022-39342CRITICAL9.8OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un...
CVE-2022-39341CRITICAL9.8OpenFGA is an authorization/permission engine. Versions prior to version 0.2.4 are vulnerable to authorization bypass un...
CVE-2022-39340MEDIUM5.3OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali...
CVE-2022-39327CRITICAL9.8Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulner...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now