2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2189MEDIUM6.1The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt...
CVE-2022-2115MEDIUM6.1The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a...
CVE-2022-2072MEDIUM6.1The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in ...
CVE-2022-2071MEDIUM6.1The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking san...
CVE-2022-1551MEDIUM6.5The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad ac...
CVE-2022-1539HIGH8.8The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to exp...
CVE-2022-0899MEDIUM6.1The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back...
CVE-2022-0594MEDIUM5.3The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author...
CVE-2022-29709HIGH7.5CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the ...
CVE-2022-36450CRITICAL9.8Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is...
CVE-2022-36446CRITICAL9.8software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CVE-2022-36444CRITICAL9.8An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 befor...
CVE-2022-24294HIGH7.5A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resou...
CVE-2022-36415HIGH7.8A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when i...
CVE-2022-36414MEDIUM6.7There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 t...
CVE-2022-1146MEDIUM6.5Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to lea...
CVE-2022-1145HIGH7.5Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install...
CVE-2022-1144HIGH8.8Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage...
CVE-2022-1143HIGH8.8Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to ...
CVE-2022-1142HIGH8.8Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to ...
CVE-2022-1141HIGH8.8Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to...
CVE-2022-1139MEDIUM6.5Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker t...
CVE-2022-1138MEDIUM6.5Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had com...
CVE-2022-1137MEDIUM6.5Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a u...
CVE-2022-1136HIGH8.8Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now