2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2473 | MEDIUM | 4.8 | 0.9% | Sep 6, 2022 | The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘templates[browsingpage][tex... |
| CVE-2022-2462 | MEDIUM | 5.3 | 2.9% | Sep 6, 2022 | The Transposh WordPress Translation plugin for WordPress is vulnerable to sensitive information disclosure to unauthenti... |
| CVE-2022-2461 | MEDIUM | 5.3 | 3.5% | Sep 6, 2022 | The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting changes by unauthenticate... |
| CVE-2022-2442 | HIGH | 7.2 | 1.3% | Sep 6, 2022 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via th... |
| CVE-2022-2438 | HIGH | 7.2 | 1.3% | Sep 6, 2022 | The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' val... |
| CVE-2022-2436 | HIGH | 8.8 | 1.3% | Sep 6, 2022 | The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]... |
| CVE-2022-2434 | HIGH | 8.8 | 1.2% | Sep 6, 2022 | The String Locator plugin for WordPress is vulnerable to deserialization of untrusted input via the 'string-locator-path... |
| CVE-2022-2433 | HIGH | 7.5 | 1.2% | Sep 6, 2022 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input ... |
| CVE-2022-2432 | MEDIUM | 4.3 | 0.5% | Sep 6, 2022 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an... |
| CVE-2022-2431 | HIGH | 8.8 | 2.5% | Sep 6, 2022 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.... |
| CVE-2022-2430 | MEDIUM | 5.4 | 0.5% | Sep 6, 2022 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Text Bloc... |
| CVE-2022-2429 | HIGH | 8 | 0.7% | Sep 6, 2022 | The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, an... |
| CVE-2022-2402 | MEDIUM | 6.5 | 0.2% | Sep 6, 2022 | The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kern... |
| CVE-2022-2233 | HIGH | 8.8 | 0.5% | Sep 6, 2022 | The Banner Cycler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.4.... |
| CVE-2022-29062 | MEDIUM | 6.5 | 0.7% | Sep 6, 2022 | Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att... |
| CVE-2022-29058 | HIGH | 7.8 | 0.5% | Sep 6, 2022 | An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line... |
| CVE-2022-29053 | LOW | 3.3 | 0.3% | Sep 6, 2022 | A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version ... |
| CVE-2022-28885 | HIGH | 7.5 | 0.4% | Sep 6, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ... |
| CVE-2022-28884 | HIGH | 7.5 | 0.4% | Sep 6, 2022 | A Denial-of-Service vulnerability was discovered in the F-Secure and WithSecure products where aerdl.dll may go into an ... |
| CVE-2022-27664 | HIGH | 7.5 | 2.5% | Sep 6, 2022 | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 conn... |
| CVE-2022-27491 | HIGH | 7.5 | 1.2% | Sep 6, 2022 | A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7... |
| CVE-2022-26470 | MEDIUM | 6.7 | 0.1% | Sep 6, 2022 | In aie, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of... |
| CVE-2022-26469 | HIGH | 7.8 | 0.2% | Sep 6, 2022 | In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation ... |
| CVE-2022-26468 | MEDIUM | 6.6 | 0.1% | Sep 6, 2022 | In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca... |
| CVE-2022-26467 | MEDIUM | 6.7 | 0.1% | Sep 6, 2022 | In rpmb, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation o... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now