2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38844 | HIGH | 8 | 1.1% | Sep 16, 2022 | CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating ... |
| CVE-2022-38843 | HIGH | 8.8 | 1.1% | Sep 16, 2022 | EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any ext... |
| CVE-2022-38808 | HIGH | 8.8 | 0.7% | Sep 16, 2022 | ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface. |
| CVE-2022-3223 | MEDIUM | 6.1 | 0.6% | Sep 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1. |
| CVE-2022-40156 | — | — | — | Sep 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-40155 | — | — | — | Sep 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-40154 | — | — | — | Sep 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-40153 | — | — | — | Sep 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-40152 | HIGH | 7.5 | 19.7% | Sep 16, 2022 | Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. I... |
| CVE-2022-40151 | HIGH | 7.5 | 1.0% | Sep 16, 2022 | Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running ... |
| CVE-2022-40150 | HIGH | 7.5 | 1.2% | Sep 16, 2022 | Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa... |
| CVE-2022-40149 | HIGH | 7.5 | 1.2% | Sep 16, 2022 | Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa... |
| CVE-2022-2913 | MEDIUM | 4.3 | 0.6% | Sep 16, 2022 | The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spo... |
| CVE-2022-2912 | MEDIUM | 4.3 | 0.5% | Sep 16, 2022 | The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logg... |
| CVE-2022-2887 | MEDIUM | 4.8 | 0.5% | Sep 16, 2022 | The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high pr... |
| CVE-2022-2877 | MEDIUM | 5.3 | 0.6% | Sep 16, 2022 | The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate ... |
| CVE-2022-2863 | MEDIUM | 4.9 | 17.7% | Sep 16, 2022 | The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it... |
| CVE-2022-2799 | MEDIUM | 4.8 | 0.5% | Sep 16, 2022 | The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could all... |
| CVE-2022-2798 | HIGH | 8 | 0.9% | Sep 16, 2022 | The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could all... |
| CVE-2022-2737 | MEDIUM | 4.8 | 0.5% | Sep 16, 2022 | The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2022-2669 | MEDIUM | 6.1 | 0.5% | Sep 16, 2022 | The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back... |
| CVE-2022-2655 | MEDIUM | 6.1 | 0.6% | Sep 16, 2022 | The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in a... |
| CVE-2022-2654 | MEDIUM | 6.1 | 0.5% | Sep 16, 2022 | The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classifie... |
| CVE-2022-2635 | MEDIUM | 4.8 | 0.5% | Sep 16, 2022 | The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2022-2575 | MEDIUM | 4.8 | 0.5% | Sep 16, 2022 | The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its setting... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now