2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38070HIGH8.8Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
CVE-2022-38068MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 a...
CVE-2022-38067MEDIUM5.3Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
CVE-2022-38064MEDIUM5.5OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission cont...
CVE-2022-38059HIGH8Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.
CVE-2022-38058MEDIUM4.3Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at WordPress.
CVE-2022-37412MEDIUM4.8Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Galerio & Urda's Better Delete Revision plu...
CVE-2022-37411HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at WordPress.
CVE-2022-37407MEDIUM5.4Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 ...
CVE-2022-37405HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin <= 2.0.1 at WordPress.
CVE-2022-37404MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Salazar's add2fav plugin <= 1.0 at W...
CVE-2022-37403MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nikhil Vaghela's Add User Role plugin <= 0.0.1...
CVE-2022-37335MEDIUM4.8Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in WHA's Word Search Puzzles game plugin <= 2.0....
CVE-2022-37299MEDIUM6.5An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file re...
CVE-2022-36878LOW3.3Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via ...
CVE-2022-36877LOW3.3Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global an...
CVE-2022-36876LOW2.4Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access acc...
CVE-2022-36875MEDIUM5.5Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 al...
CVE-2022-36874MEDIUM6.2Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows...
CVE-2022-36873MEDIUM6.5Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.220811...
CVE-2022-36872MEDIUM6.5Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for ...
CVE-2022-36871MEDIUM6.5Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for G...
CVE-2022-36870MEDIUM6.5Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and...
CVE-2022-36869MEDIUM6.1Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attac...
CVE-2022-36867MEDIUM5.5Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive inf...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now