2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34774MEDIUM5.3Tabit - Arbitrary account modification. One of the endpoints mapped by the tiny URL, was a page where an adversary can m...
CVE-2022-34773CRITICAL9.8Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addre...
CVE-2022-34772HIGH8.8Tabit - password enumeration. Description: Tabit - password enumeration. The passwords for the Tabit system is a 4 digit...
CVE-2022-34771LOW3.5Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits ...
CVE-2022-34770HIGH7.5Tabit - sensitive information disclosure. Several APIs on the web system display, without authorization, sensitive infor...
CVE-2022-34347HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress.
CVE-2022-34149CRITICAL9.8Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
CVE-2022-33900HIGH7.2PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress.
CVE-2022-2873MEDIUM5.5An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a...
CVE-2022-2600MEDIUM5.4The Auto-hyperlink URLs WordPress plugin through 5.4.1 does not set rel="noopener noreferer" on generated links, which c...
CVE-2022-2594HIGH8.8The Advanced Custom Fields WordPress plugin before 5.12.3, Advanced Custom Fields Pro WordPress plugin before 5.12.3 all...
CVE-2022-2593HIGH7.2The Better Search Replace WordPress plugin before 1.4.1 does not properly sanitise and escape table data before insertin...
CVE-2022-2558MEDIUM5.3The Simple Job Board WordPress plugin before 2.10.0 is susceptible to Directory Listing which allows the public listing ...
CVE-2022-2557HIGH8.8The Team WordPress plugin before 4.1.2 contains a file which could allow any authenticated users to download arbitrary f...
CVE-2022-2555MEDIUM6.5The Yotpo Reviews for WooCommerce WordPress plugin through 2.0.4 lacks nonce check when updating its settings, which cou...
CVE-2022-2552MEDIUM5.3The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information a...
CVE-2022-2551HIGH7.5The Duplicator WordPress plugin before 1.4.7 discloses the url of the a backup to unauthenticated visitors accessing the...
CVE-2022-2544HIGH7.5The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, makin...
CVE-2022-2532MEDIUM6.1The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-2407MEDIUM4.8The WP phpMyAdmin WordPress plugin before 5.2.0.4 does not escape some of its settings, which could allow high privilege...
CVE-2022-2392MEDIUM6.5The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that ca...
CVE-2022-2389MEDIUM4.3The Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By Autonami Wor...
CVE-2022-2388MEDIUM6.5The WP Coder WordPress plugin before 2.5.3 does not have CSRF check in place when deleting code created by the plugin, w...
CVE-2022-2383MEDIUM6.1The Feed Them Social WordPress plugin before 3.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2022-2382MEDIUM4.3The Product Slider for WooCommerce WordPress plugin before 2.5.7 has flawed CSRF checks and lack authorisation in some o...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now