2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39219MEDIUM6.5Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1....
CVE-2022-40928HIGH7.2Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_applica...
CVE-2022-40927HIGH7.2Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designa...
CVE-2022-40926HIGH7.2Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_t...
CVE-2022-40925HIGH7.2Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" fi...
CVE-2022-40924HIGH7.2Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" f...
CVE-2022-40404HIGH8.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
CVE-2022-40403HIGH7.2Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit...
CVE-2022-40402HIGH8.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_...
CVE-2022-3299MEDIUM6.5A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability i...
CVE-2022-3295HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-3135MEDIUM4.8The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-3119HIGH7.5The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its set...
CVE-2022-3098MEDIUM4.3The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which c...
CVE-2022-3076HIGH7.2The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary file...
CVE-2022-3074MEDIUM4.8The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users t...
CVE-2022-3070MEDIUM4.8The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users su...
CVE-2022-3069MEDIUM4.8The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users suc...
CVE-2022-3062MEDIUM6.1The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes...
CVE-2022-3025MEDIUM5.4The Bitcoin / Altcoin Faucet WordPress plugin through 1.6.0 does not have any CSRF check when saving its settings, allow...
CVE-2022-3024MEDIUM5.4The Simple Bitcoin Faucets WordPress plugin through 1.7.0 does not have any authorisation and CSRF in an AJAX action, al...
CVE-2022-2987HIGH7.5The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF ...
CVE-2022-2926MEDIUM4.9The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privil...
CVE-2022-2903HIGH7.2The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could le...
CVE-2022-2405MEDIUM4.3The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now