2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2559HIGH7.2The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo...
CVE-2022-2556LOW2.7The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perfo...
CVE-2022-2538MEDIUM6.1The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an ...
CVE-2022-2537MEDIUM6.1The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters ...
CVE-2022-2374MEDIUM4.8The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, whic...
CVE-2022-2373MEDIUM5.3The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing u...
CVE-2022-2267MEDIUM4.3The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as ...
CVE-2022-2261HIGH7.2The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require...
CVE-2022-2080MEDIUM4.3The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher ...
CVE-2022-2034MEDIUM5.3The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing ...
CVE-2022-1663MEDIUM6.5The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preve...
CVE-2022-1123HIGH7.2The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz...
CVE-2022-36034HIGH7.5nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions o...
CVE-2022-36033MEDIUM6.1jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup ma...
CVE-2022-27558HIGH7.5HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced ...
CVE-2022-27547HIGH7.4HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to tr...
CVE-2022-27546MEDIUM6.1HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-...
CVE-2022-36200HIGH7.5In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
CVE-2022-35962MEDIUM5.7Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version ...
CVE-2022-31677MEDIUM5.4An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticati...
CVE-2022-2961HIGH7A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition...
CVE-2022-2953MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a d...
CVE-2022-1204MEDIUM5.5A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user conne...
CVE-2022-1199HIGH7.5A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio...
CVE-2022-1198MEDIUM5.5A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to cras...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now