2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2241MEDIUM6.1The Featured Image from URL (FIFU) WordPress plugin before 4.0.1 does not have CSRF check in place when updating its set...
CVE-2022-2215MEDIUM4.8The GiveWP WordPress plugin before 2.21.3 does not properly sanitise and escape the currency settings, which could allow...
CVE-2022-2184HIGH8.8The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-si...
CVE-2022-2181MEDIUM6.1The Advanced WordPress Reset WordPress plugin before 1.6 does not escape some generated URLs before outputting them back...
CVE-2022-2171MEDIUM5.4The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could a...
CVE-2022-2170MEDIUM4.8The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its ...
CVE-2022-26310HIGH8.8Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with a...
CVE-2022-26309HIGH8.8Pandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of pr...
CVE-2022-26308MEDIUM5.4Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with...
CVE-2022-1950CRITICAL9.8The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement vi...
CVE-2022-1906MEDIUM6.1The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via...
CVE-2022-1600MEDIUM5.3The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOT...
CVE-2022-1585HIGH7.5The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download func...
CVE-2022-1561MEDIUM4.3Lura and KrakenD-CE versions older than v2.0.2 and KrakenD-EE versions older than v2.0.0 do not sanitize URL parameters ...
CVE-2022-1324MEDIUM4.8The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-pri...
CVE-2022-0598MEDIUM4.8The Login with phone number WordPress plugin before 1.3.8 does not sanitise and escape plugin settings which could allow...
CVE-2022-27255CRITICAL9.8In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer over...
CVE-2022-36799HIGH7.2This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has ...
CVE-2022-35716MEDIUM6.5IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7.1.2.7, and 7.2.0.0 thro...
CVE-2022-34338MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege...
CVE-2022-33169MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for user...
CVE-2022-32750MEDIUM5.4IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-31776HIGH8.8IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-31775CRITICAL9.1IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-31774MEDIUM5.4IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now