2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35238MEDIUM5.3Unauthenticated Plugin Settings Change vulnerability in Awesome Filterable Portfolio plugin <= 1.9.7 at WordPress.
CVE-2022-23144CRITICAL9.1There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers coul...
CVE-2022-40869CRITICAL9.8Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with ...
CVE-2022-40865CRITICAL9.8Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the req...
CVE-2022-40864CRITICAL9.8Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement ...
CVE-2022-40862CRITICAL9.8Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with ...
CVE-2022-40860CRITICAL9.8Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with...
CVE-2022-40853CRITICAL9.8Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set
CVE-2022-40213MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin ...
CVE-2022-40093HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40092HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40091HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-3144MEDIUM4.8The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve...
CVE-2022-38703MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Max Foundry Button Plugin MaxButtons plugin <=...
CVE-2022-38095MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.3 at...
CVE-2022-37339MEDIUM5.4Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Meet My Team plugin <= 2.0.5 a...
CVE-2022-37338MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <...
CVE-2022-37330MEDIUM5.4Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA Crossword plugin <= 1.1.10 at WordPr...
CVE-2022-36798HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2....
CVE-2022-35257HIGH7.8A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious a...
CVE-2022-35253Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-35252LOW3.7When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when l...
CVE-2022-30121MEDIUM6.7The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only fo...
CVE-2022-2937MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title & Descr...
CVE-2022-27492HIGH7.8An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now