2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38663 | MEDIUM | 6.5 | 0.8% | Aug 23, 2022 | Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log... |
| CVE-2022-37428 | MEDIUM | 6.5 | 1.2% | Aug 23, 2022 | PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upo... |
| CVE-2022-2946 | HIGH | 7.8 | 0.5% | Aug 23, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0246. |
| CVE-2022-37113 | CRITICAL | 9.8 | 13.4% | Aug 23, 2022 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php |
| CVE-2022-37112 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php |
| CVE-2022-37111 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php |
| CVE-2022-36405 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 ... |
| CVE-2022-36394 | HIGH | 8.8 | 0.7% | Aug 23, 2022 | Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. |
| CVE-2022-36389 | HIGH | 8.8 | 0.3% | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in WordPlus Better Messages plugin <= 1.9.9.148 at WordPress. |
| CVE-2022-36379 | HIGH | 8.8 | 0.4% | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) leading to plugin settings update in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 a... |
| CVE-2022-36347 | MEDIUM | 5.4 | 0.5% | Aug 23, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest pl... |
| CVE-2022-36341 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash s... |
| CVE-2022-36292 | HIGH | 8.8 | 0.3% | Aug 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerabilities in WPChill Gallery PhotoBlocks plugin <= 1.2.6 at WordPress. |
| CVE-2022-36288 | HIGH | 8.8 | 0.3% | Aug 23, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. |
| CVE-2022-36285 | HIGH | 7.2 | 0.9% | Aug 23, 2022 | Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at... |
| CVE-2022-36282 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2... |
| CVE-2022-35726 | CRITICAL | 9.8 | 0.6% | Aug 23, 2022 | Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress. |
| CVE-2022-35242 | MEDIUM | 5.3 | 0.5% | Aug 23, 2022 | Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at... |
| CVE-2022-35235 | MEDIUM | 4.9 | 0.9% | Aug 23, 2022 | Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. |
| CVE-2022-34868 | MEDIUM | 6.5 | 0.9% | Aug 23, 2022 | Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress. |
| CVE-2022-34658 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager ... |
| CVE-2022-34648 | MEDIUM | 5.4 | 0.4% | Aug 23, 2022 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO fi... |
| CVE-2022-33142 | MEDIUM | 6.5 | 0.9% | Aug 23, 2022 | Authenticated (subscriber+) Denial Of Service (DoS) vulnerability in WordPlus WordPress Better Messages plugin <= 1.9.10... |
| CVE-2022-2965 | MEDIUM | 4.3 | 0.6% | Aug 23, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository notrinos/notrinoserp prior to 0.7. |
| CVE-2022-29476 | MEDIUM | 6.1 | 0.4% | Aug 23, 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in 8 Degree Themes otification Bar for WordPress plugin ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now