2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2189 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt... |
| CVE-2022-2115 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a... |
| CVE-2022-2072 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2022-2071 | MEDIUM | 6.1 | 0.3% | Jul 25, 2022 | The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking san... |
| CVE-2022-1551 | MEDIUM | 6.5 | 0.8% | Jul 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad ac... |
| CVE-2022-1539 | HIGH | 8.8 | 1.2% | Jul 25, 2022 | The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when generating the CSV to exp... |
| CVE-2022-0899 | MEDIUM | 6.1 | 1.0% | Jul 25, 2022 | The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back... |
| CVE-2022-0594 | MEDIUM | 5.3 | 1.5% | Jul 25, 2022 | The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper author... |
| CVE-2022-29709 | HIGH | 7.5 | 1.3% | Jul 25, 2022 | CommuniLink Internet Limited CLink Office v2.0 was discovered to contain multiple SQL injection vulnerabilities via the ... |
| CVE-2022-36450 | CRITICAL | 9.8 | 19.6% | Jul 25, 2022 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is... |
| CVE-2022-36446 | CRITICAL | 9.8 | 96.0% | Jul 25, 2022 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. |
| CVE-2022-36444 | CRITICAL | 9.8 | 0.8% | Jul 25, 2022 | An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 befor... |
| CVE-2022-24294 | HIGH | 7.5 | 1.6% | Jul 24, 2022 | A regular expression used in Apache MXNet (incubating) is vulnerable to a potential denial-of-service by excessive resou... |
| CVE-2022-36415 | HIGH | 7.8 | 0.2% | Jul 23, 2022 | A DLL hijacking vulnerability exists in the uninstaller in Scooter Beyond Compare 1.8a through 4.4.2 before 4.4.3 when i... |
| CVE-2022-36414 | MEDIUM | 6.7 | 0.2% | Jul 23, 2022 | There is an elevation of privilege breakout vulnerability in the Windows EXE installer in Scooter Beyond Compare 4.2.0 t... |
| CVE-2022-1146 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to lea... |
| CVE-2022-1145 | HIGH | 7.5 | 0.5% | Jul 23, 2022 | Use after free in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install... |
| CVE-2022-1144 | HIGH | 8.8 | 0.6% | Jul 23, 2022 | Use after free in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage... |
| CVE-2022-1143 | HIGH | 8.8 | 0.7% | Jul 23, 2022 | Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to ... |
| CVE-2022-1142 | HIGH | 8.8 | 0.6% | Jul 23, 2022 | Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to ... |
| CVE-2022-1141 | HIGH | 8.8 | 0.7% | Jul 23, 2022 | Use after free in File Manager in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to... |
| CVE-2022-1139 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60 allowed a remote attacker t... |
| CVE-2022-1138 | MEDIUM | 6.5 | 0.7% | Jul 23, 2022 | Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who had com... |
| CVE-2022-1137 | MEDIUM | 6.5 | 0.5% | Jul 23, 2022 | Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a u... |
| CVE-2022-1136 | HIGH | 8.8 | 0.5% | Jul 23, 2022 | Use after free in Tab Strip in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now