2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3244MEDIUM4.2The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not have authorisation in some places, which could allo...
CVE-2022-3243HIGH7.2The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before u...
CVE-2022-3206MEDIUM5.9The Passster WordPress plugin before 3.5.5.5.2 stores the password inside a cookie named "passster" using base64 encodin...
CVE-2022-3151MEDIUM4.3The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when deleting cursors, which could...
CVE-2022-3150HIGH7.2The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a...
CVE-2022-3149MEDIUM6.1The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors,...
CVE-2022-3139MEDIUM4.8The We’re Open! WordPress plugin before 1.42 does not sanitise and escape some of its settings, which could allow high p...
CVE-2022-3131HIGH7.2The Search Logger WordPress plugin through 0.9 does not properly sanitise and escape a parameter before using it in a SQ...
CVE-2022-3126MEDIUM4.3The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could...
CVE-2022-3082MEDIUM6.5The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJA...
CVE-2022-2834MEDIUM5.3The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and gu...
CVE-2022-2574MEDIUM4.8The Meks Easy Social Share WordPress plugin before 1.2.8 does not sanitise and escape some of its settings, which could ...
CVE-2022-2563MEDIUM4.8The Tutor LMS WordPress plugin before 2.0.10 does not escape some course parameters, which could allow high privilege us...
CVE-2022-3535Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3534HIGH8A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function...
CVE-2022-3533MEDIUM5.7A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_...
CVE-2022-3532Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3531Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3501HIGH7.5Article template contents with sensitive data could be accessed from agents without permissions.
CVE-2022-3281HIGH7.5WAGO Series PFC100/PFC200, Series Touch Panel 600, Compact Controller CC100 and Edge Controller in multiple versions are...
CVE-2022-39052MEDIUM6.5An external attacker is able to send a specially crafted email (with many recipients) and trigger a potential DoS of the...
CVE-2022-2052CRITICAL9.8Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use t...
CVE-2022-42983HIGH8.8anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens.
CVE-2022-42980CRITICAL9.8go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
CVE-2022-42975HIGH7.5socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now