2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38844HIGH8CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating ...
CVE-2022-38843HIGH8.8EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any ext...
CVE-2022-38808HIGH8.8ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
CVE-2022-3223MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
CVE-2022-40156Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-40155Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-40154Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-40153Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-40152HIGH7.5Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. I...
CVE-2022-40151HIGH7.5Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running ...
CVE-2022-40150HIGH7.5Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa...
CVE-2022-40149HIGH7.5Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the pa...
CVE-2022-2913MEDIUM4.3The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spo...
CVE-2022-2912MEDIUM4.3The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logg...
CVE-2022-2887MEDIUM4.8The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high pr...
CVE-2022-2877MEDIUM5.3The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate ...
CVE-2022-2863MEDIUM4.9The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it...
CVE-2022-2799MEDIUM4.8The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could all...
CVE-2022-2798HIGH8The Affiliates Manager WordPress plugin before 2.9.14 does not validate and sanitise the affiliate data, which could all...
CVE-2022-2737MEDIUM4.8The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-2669MEDIUM6.1The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back...
CVE-2022-2655MEDIUM6.1The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in a...
CVE-2022-2654MEDIUM6.1The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classifie...
CVE-2022-2635MEDIUM4.8The Autoptimize WordPress plugin before 3.1.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-2575MEDIUM4.8The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its setting...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now