2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36265HIGH7.2In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists a Hidden system command web page. After performing a re...
CVE-2022-36264CRITICAL9.1In Airspan AirSpot 5410 version 0.3.4.1-4 and under there exists an Unauthenticated remote Arbitrary File Upload vulnera...
CVE-2022-35493MEDIUM6.1A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose...
CVE-2022-2713CRITICAL9.8Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.
CVE-2022-35490CRITICAL9.8Zammad 5.2.0 is vulnerable to privilege escalation. Zammad has a prevention against brute-force attacks trying to guess ...
CVE-2022-35489MEDIUM6.5In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all organizations of the system ra...
CVE-2022-35488HIGH7.5In Zammad 5.2.0, an attacker could manipulate the rate limiting in the 'forgot password' feature of Zammad, and thereby ...
CVE-2022-35487HIGH7.5Zammad 5.2.0 suffers from Incorrect Access Control. Zammad did not correctly perform authorization on certain attachment...
CVE-2022-2460CRITICAL9.8The WPDating WordPress plugin before 7.4.0 does not properly escape user input before concatenating it to certain SQL qu...
CVE-2022-2426MEDIUM4.8The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high ...
CVE-2022-2425MEDIUM4.8The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-2424MEDIUM4.8The Google Maps Anywhere WordPress plugin through 1.2.6.3 does not sanitise and escape any of its settings, which could ...
CVE-2022-2423MEDIUM4.8The DW Promobar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-2412MEDIUM4.8The Better Tag Cloud WordPress plugin through 0.99.5 does not sanitise and escape some of its settings, which could allo...
CVE-2022-2411MEDIUM4.8The Auto More Tag WordPress plugin through 4.0.0 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-2410MEDIUM4.8The mTouch Quiz WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-2409MEDIUM4.8The Rough Chart WordPress plugin through 1.0.0 does not properly escape chart data label, which could allow high privile...
CVE-2022-2398MEDIUM4.8The WordPress Comments Fields WordPress plugin before 4.1 does not escape Field Error Message, which could allow high-pr...
CVE-2022-2395MEDIUM4.8The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such...
CVE-2022-2391MEDIUM5.4The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as l...
CVE-2022-2386MEDIUM6.1The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it ba...
CVE-2022-2372MEDIUM4.8The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2022-2371MEDIUM5.4The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users wi...
CVE-2022-2367HIGH7.5The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, t...
CVE-2022-2357HIGH7.5The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now