2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28671HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2....
CVE-2022-28670HIGH7.8This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Read...
CVE-2022-28669HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2....
CVE-2022-26120HIGH8.8Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] i...
CVE-2022-26118MEDIUM6.7A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 ...
CVE-2022-26117HIGH8.8An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8....
CVE-2022-23438MEDIUM6.1An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiO...
CVE-2022-22445MEDIUM6.5An attacker that gains service access to the FSP (POWER9 only) or gains admin authority to a partition can compromise pa...
CVE-2022-32387HIGH7.5In Kentico before 13.0.66, attackers can achieve Denial of Service via a crafted request to the GetResource handler.
CVE-2022-2444HIGH8.8The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to deserialization of untrust...
CVE-2022-2443HIGH8.8The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin...
CVE-2022-2437CRITICAL9.8The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untru...
CVE-2022-2435HIGH8.8The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1...
CVE-2022-2224MEDIUM4.3The WordPress plugin Gallery for Social Photo is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2022-2223MEDIUM4.3The WordPress plugin Image Slider is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1.121 d...
CVE-2022-2117MEDIUM5.3The GiveWP plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 2.20...
CVE-2022-2108MEDIUM5.3The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and rev...
CVE-2022-2101MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter...
CVE-2022-2039HIGH8.8The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2022-2001HIGH8.8The DX Share Selection plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2022-23745HIGH7.5A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could resul...
CVE-2022-22304MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent fo...
CVE-2022-1912HIGH8.8The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2022-1565HIGH7.2The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo...
CVE-2022-35741CRITICAL9.8Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vul...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now