2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2473MEDIUM4.8The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][tex...
CVE-2022-2462MEDIUM5.3The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenti...
CVE-2022-2461MEDIUM5.3The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate...
CVE-2022-2442HIGH7.2The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via th...
CVE-2022-2438HIGH7.2The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' val...
CVE-2022-2436HIGH8.8The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]...
CVE-2022-2434HIGH8.8The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path...
CVE-2022-2433HIGH7.5The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input ...
CVE-2022-2432MEDIUM4.3The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an...
CVE-2022-2431HIGH8.8The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2....
CVE-2022-2430MEDIUM5.4The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Bloc...
CVE-2022-2429HIGH8The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, an...
CVE-2022-2402MEDIUM6.5The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kern...
CVE-2022-2233HIGH8.8The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4....
CVE-2022-29062MEDIUM6.5Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att...
CVE-2022-29058HIGH7.8An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line...
CVE-2022-29053LOW3.3A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version ...
CVE-2022-28885HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ...
CVE-2022-28884HIGH7.5A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an ...
CVE-2022-27664HIGH7.5In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 conn...
CVE-2022-27491HIGH7.5A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7...
CVE-2022-26470MEDIUM6.7In aie, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of...
CVE-2022-26469HIGH7.8In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation ...
CVE-2022-26468MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-26467MEDIUM6.7In rpmb, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation o...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now