2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35958Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-37458. Reason: This candidate is a reservation d...
CVE-2022-35954MEDIUM5The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio...
CVE-2022-35948MEDIUM5.3undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection...
CVE-2022-2822HIGH7.5An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess us...
CVE-2022-2821HIGH7.5Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2820HIGH8.2Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2819HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
CVE-2022-2818HIGH8.8Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2....
CVE-2022-2814MEDIUM6.1A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Aff...
CVE-2022-2813HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is a...
CVE-2022-2812CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects u...
CVE-2022-2811MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unkn...
CVE-2022-2535MEDIUM5.3The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited ...
CVE-2022-2384MEDIUM4.8The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing ...
CVE-2022-2381HIGH8.8The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School ...
CVE-2022-2379HIGH7.5The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us...
CVE-2022-2378MEDIUM6.1The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it ba...
CVE-2022-2354HIGH7.2The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the s...
CVE-2022-2314CRITICAL9.8The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
CVE-2022-2180CRITICAL9.8The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any autho...
CVE-2022-2152MEDIUM4.8The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privile...
CVE-2022-2116MEDIUM6.1The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them ba...
CVE-2022-35949CRITICAL9.8undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forge...
CVE-2022-35942CRITICAL10Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended fil...
CVE-2022-35956CRITICAL9.8This Rails gem adds two methods to the ActiveRecord::Base class that allow you to update many records on a single databa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now