2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36265 | HIGH | 7.2 | 1.1% | Aug 8, 2022 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a re... |
| CVE-2022-36264 | CRITICAL | 9.1 | 1.2% | Aug 8, 2022 | In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnera... |
| CVE-2022-35493 | MEDIUM | 6.1 | 1.4% | Aug 8, 2022 | A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose... |
| CVE-2022-2713 | CRITICAL | 9.8 | 1.0% | Aug 8, 2022 | Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. |
| CVE-2022-35490 | CRITICAL | 9.8 | 0.7% | Aug 8, 2022 | Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess ... |
| CVE-2022-35489 | MEDIUM | 6.5 | 0.6% | Aug 8, 2022 | In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system ra... |
| CVE-2022-35488 | HIGH | 7.5 | 0.7% | Aug 8, 2022 | In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby ... |
| CVE-2022-35487 | HIGH | 7.5 | 0.7% | Aug 8, 2022 | Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment... |
| CVE-2022-2460 | CRITICAL | 9.8 | 0.9% | Aug 8, 2022 | The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL qu... |
| CVE-2022-2426 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high ... |
| CVE-2022-2425 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-2424 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could ... |
| CVE-2022-2423 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-2412 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allo... |
| CVE-2022-2411 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2022-2410 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-2409 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privile... |
| CVE-2022-2398 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-pr... |
| CVE-2022-2395 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such... |
| CVE-2022-2391 | MEDIUM | 5.4 | 0.5% | Aug 8, 2022 | The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as l... |
| CVE-2022-2386 | MEDIUM | 6.1 | 0.5% | Aug 8, 2022 | The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2022-2372 | MEDIUM | 4.8 | 0.5% | Aug 8, 2022 | The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2022-2371 | MEDIUM | 5.4 | 0.5% | Aug 8, 2022 | The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users wi... |
| CVE-2022-2367 | HIGH | 7.5 | 1.0% | Aug 8, 2022 | The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, t... |
| CVE-2022-2357 | HIGH | 7.5 | 1.2% | Aug 8, 2022 | The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now