2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2377 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing an... |
| CVE-2022-2375 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings,... |
| CVE-2022-2362 | HIGH | 7.5 | 1.0% | Aug 22, 2022 | The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PH... |
| CVE-2022-2361 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | The WP Social Chat WordPress plugin before 6.0.5 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-2312 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The Student Result or Employee Database WordPress plugin before 1.7.5 does not have CSRF in its AJAX actions, allowing a... |
| CVE-2022-2276 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The WP Edit Menu WordPress plugin before 1.5.0 does not have authorisation and CSRF in an AJAX action, which could allow... |
| CVE-2022-2275 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The WP Edit Menu WordPress plugin before 1.5.0 does not have CSRF in an AJAX action, which could allow attackers to make... |
| CVE-2022-2198 | MEDIUM | 4.3 | 0.6% | Aug 22, 2022 | The WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check author... |
| CVE-2022-2172 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The LinkWorth WordPress plugin before 3.3.4 does not implement nonce checks, which could allow attackers to make a logge... |
| CVE-2022-25812 | HIGH | 7.2 | 1.4% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not validate its debug settings, which could allo... |
| CVE-2022-25811 | HIGH | 7.2 | 1.2% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 does not sanitise and escape the order and orderby pa... |
| CVE-2022-25810 | MEDIUM | 6.5 | 0.9% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin through 1.0.8 exposes a couple of sensitive actions such has “tp_re... |
| CVE-2022-1932 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting th... |
| CVE-2022-1322 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, w... |
| CVE-2022-1251 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile ... |
| CVE-2022-0446 | MEDIUM | 4.8 | 0.4% | Aug 22, 2022 | The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h... |
| CVE-2022-2932 | MEDIUM | 6.1 | 0.7% | Aug 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2. |
| CVE-2022-2890 | MEDIUM | 5.4 | 0.7% | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-2930 | HIGH | 7.8 | 0.3% | Aug 22, 2022 | Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3. |
| CVE-2022-1340 | MEDIUM | 5.4 | 0.4% | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-2927 | CRITICAL | 9.8 | 0.8% | Aug 22, 2022 | Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. |
| CVE-2022-2841 | LOW | 2.7 | 3.7% | Aug 22, 2022 | A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problemati... |
| CVE-2022-36251 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php. |
| CVE-2022-36198 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin... |
| CVE-2022-34916 | CRITICAL | 9.8 | 2.3% | Aug 21, 2022 | Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now