2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2559 | HIGH | 7.2 | 0.9% | Aug 29, 2022 | The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo... |
| CVE-2022-2556 | LOW | 2.7 | 0.6% | Aug 29, 2022 | The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perfo... |
| CVE-2022-2538 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an ... |
| CVE-2022-2537 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters ... |
| CVE-2022-2374 | MEDIUM | 4.8 | 0.5% | Aug 29, 2022 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, whic... |
| CVE-2022-2373 | MEDIUM | 5.3 | 1.4% | Aug 29, 2022 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing u... |
| CVE-2022-2267 | MEDIUM | 4.3 | 0.6% | Aug 29, 2022 | The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as ... |
| CVE-2022-2261 | HIGH | 7.2 | 1.1% | Aug 29, 2022 | The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require... |
| CVE-2022-2080 | MEDIUM | 4.3 | 0.6% | Aug 29, 2022 | The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher ... |
| CVE-2022-2034 | MEDIUM | 5.3 | 1.8% | Aug 29, 2022 | The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing ... |
| CVE-2022-1663 | MEDIUM | 6.5 | 0.5% | Aug 29, 2022 | The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preve... |
| CVE-2022-1123 | HIGH | 7.2 | 1.0% | Aug 29, 2022 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz... |
| CVE-2022-36034 | HIGH | 7.5 | 0.8% | Aug 29, 2022 | nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions o... |
| CVE-2022-36033 | MEDIUM | 6.1 | 1.2% | Aug 29, 2022 | jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup ma... |
| CVE-2022-27558 | HIGH | 7.5 | 0.5% | Aug 29, 2022 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced ... |
| CVE-2022-27547 | HIGH | 7.4 | 0.4% | Aug 29, 2022 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to tr... |
| CVE-2022-27546 | MEDIUM | 6.1 | 0.5% | Aug 29, 2022 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-... |
| CVE-2022-36200 | HIGH | 7.5 | 1.8% | Aug 29, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed. |
| CVE-2022-35962 | MEDIUM | 5.7 | 0.9% | Aug 29, 2022 | Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version ... |
| CVE-2022-31677 | MEDIUM | 5.4 | 0.4% | Aug 29, 2022 | An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticati... |
| CVE-2022-2961 | HIGH | 7 | 0.3% | Aug 29, 2022 | A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition... |
| CVE-2022-2953 | MEDIUM | 5.5 | 0.5% | Aug 29, 2022 | LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a d... |
| CVE-2022-1204 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user conne... |
| CVE-2022-1199 | HIGH | 7.5 | 1.5% | Aug 29, 2022 | A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio... |
| CVE-2022-1198 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to cras... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now