2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3244 | MEDIUM | 4.2 | 0.4% | Oct 17, 2022 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allo... |
| CVE-2022-3243 | HIGH | 7.2 | 1.0% | Oct 17, 2022 | The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before u... |
| CVE-2022-3206 | MEDIUM | 5.9 | 0.5% | Oct 17, 2022 | The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encodin... |
| CVE-2022-3151 | MEDIUM | 4.3 | 0.3% | Oct 17, 2022 | The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could... |
| CVE-2022-3150 | HIGH | 7.2 | 0.9% | Oct 17, 2022 | The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2022-3149 | MEDIUM | 6.1 | 0.3% | Oct 17, 2022 | The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors,... |
| CVE-2022-3139 | MEDIUM | 4.8 | 0.5% | Oct 17, 2022 | The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2022-3131 | HIGH | 7.2 | 0.9% | Oct 17, 2022 | The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQ... |
| CVE-2022-3126 | MEDIUM | 4.3 | 0.3% | Oct 17, 2022 | The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could... |
| CVE-2022-3082 | MEDIUM | 6.5 | 0.4% | Oct 17, 2022 | The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJA... |
| CVE-2022-2834 | MEDIUM | 5.3 | 0.8% | Oct 17, 2022 | The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and gu... |
| CVE-2022-2574 | MEDIUM | 4.8 | 0.5% | Oct 17, 2022 | The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could ... |
| CVE-2022-2563 | MEDIUM | 4.8 | 0.6% | Oct 17, 2022 | The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege us... |
| CVE-2022-3535 | — | — | — | Oct 17, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3534 | HIGH | 8 | 0.6% | Oct 17, 2022 | A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function... |
| CVE-2022-3533 | MEDIUM | 5.7 | 0.4% | Oct 17, 2022 | A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_... |
| CVE-2022-3532 | — | — | — | Oct 17, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3531 | — | — | — | Oct 17, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3501 | HIGH | 7.5 | 0.4% | Oct 17, 2022 | Article template contents with sensitive data could be accessed from agents without permissions. |
| CVE-2022-3281 | HIGH | 7.5 | 0.7% | Oct 17, 2022 | WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are... |
| CVE-2022-39052 | MEDIUM | 6.5 | 0.6% | Oct 17, 2022 | An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the... |
| CVE-2022-2052 | CRITICAL | 9.8 | 0.6% | Oct 17, 2022 | Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use t... |
| CVE-2022-42983 | HIGH | 8.8 | 1.2% | Oct 17, 2022 | anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens. |
| CVE-2022-42980 | CRITICAL | 9.8 | 0.8% | Oct 17, 2022 | go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key. |
| CVE-2022-42975 | HIGH | 7.5 | 0.5% | Oct 17, 2022 | socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now