2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2377MEDIUM4.3The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing an...
CVE-2022-2375MEDIUM5.4The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings,...
CVE-2022-2362HIGH7.5The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PH...
CVE-2022-2361MEDIUM4.8The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-2312MEDIUM5.4The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing a...
CVE-2022-2276MEDIUM4.3The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow...
CVE-2022-2275MEDIUM4.3The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make...
CVE-2022-2198MEDIUM4.3The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author...
CVE-2022-2172MEDIUM4.3The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logge...
CVE-2022-25812HIGH7.2The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allo...
CVE-2022-25811HIGH7.2The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa...
CVE-2022-25810MEDIUM6.5The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_re...
CVE-2022-1932MEDIUM6.1The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting th...
CVE-2022-1322MEDIUM4.8The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, w...
CVE-2022-1251MEDIUM4.3The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile ...
CVE-2022-0446MEDIUM4.8The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h...
CVE-2022-2932MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.
CVE-2022-2890MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-2930HIGH7.8Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-1340MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-2927CRITICAL9.8Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
CVE-2022-2841LOW2.7A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problemati...
CVE-2022-36251MEDIUM6.1Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
CVE-2022-36198CRITICAL9.8Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin...
CVE-2022-34916CRITICAL9.8Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now