2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-33177MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPdevelop/Oplugins Booking Calendar plugin <= 9.2.1 at WordPress lead...
CVE-2022-32264HIGH7.5sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling ...
CVE-2022-31860CRITICAL9.8An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule...
CVE-2022-31790HIGH7.5WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication serv...
CVE-2022-30298HIGH7.8An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has al...
CVE-2022-2945LOW2.7The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up ...
CVE-2022-2943MEDIUM4.9The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions ...
CVE-2022-2941MEDIUM4.8The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and i...
CVE-2022-2939MEDIUM5.3The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including...
CVE-2022-2936MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Video Link values...
CVE-2022-2935MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media Image U...
CVE-2022-2934MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image UR...
CVE-2022-2735HIGH7.8A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for i...
CVE-2022-2718MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v...
CVE-2022-2717MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection v...
CVE-2022-2716MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Edi...
CVE-2022-2695MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption'...
CVE-2022-2633HIGH8.2The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side reques...
CVE-2022-2542HIGH8.8The uContext for Clickbank plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in v...
CVE-2022-2541HIGH8.8The uContext for Amazon plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers...
CVE-2022-2540HIGH8.8The Link Optimizer Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in vers...
CVE-2022-2518MEDIUM6.1The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to...
CVE-2022-2517MEDIUM5.4The Beaver Builder – WordPress Page Builder for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Caption ...
CVE-2022-2516MEDIUM5.4The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post/page ...
CVE-2022-2515MEDIUM5.4The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now