2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2151MEDIUM4.8The Best Contact Management Software WordPress plugin through 3.7.3 does not sanitise and escape its settings, allowing ...
CVE-2022-2149MEDIUM4.8The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privile...
CVE-2022-2148MEDIUM4.8The LinkedIn Company Updates WordPress plugin through 1.5.3 does not sanitise and escape its settings, allowing high pri...
CVE-2022-2146MEDIUM6.1The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them bac...
CVE-2022-2144MEDIUM4.3The Jquery Validation For Contact Form 7 WordPress plugin before 5.3 does not have CSRF check in place when updating its...
CVE-2022-2133MEDIUM5.3The OAuth Single Sign On WordPress plugin before 6.22.6 doesn't validate that OAuth access token requests are legitimate...
CVE-2022-2118MEDIUM4.8The 404s WordPress plugin before 3.5.1 does not sanitise and escape its fields, allowing high privilege users such as ad...
CVE-2022-2114MEDIUM4.8The Data Tables Generator by Supsystic WordPress plugin before 1.10.20 does not sanitise and escape some of its Table se...
CVE-2022-2100MEDIUM4.8The Page Generator WordPress plugin before 1.6.5 does not sanitise and escape its settings, allowing high privilege user...
CVE-2022-2099MEDIUM4.8The WooCommerce WordPress plugin before 6.6.0 is vulnerable to stored HTML injection due to lack of escaping and sanitiz...
CVE-2022-2090MEDIUM6.1The Discount Rules for WooCommerce WordPress plugin before 2.4.2 does not escape a parameter before outputting it back i...
CVE-2022-1933MEDIUM6.1The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response...
CVE-2022-1672HIGH8.8The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions s...
CVE-2022-36126HIGH7.2An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function ...
CVE-2022-35906LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35905LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35904LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35903LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35902LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35901LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35900LOW3.3An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected ve...
CVE-2022-35890CRITICAL9.8An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client...
CVE-2022-32434HIGH7.8EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d.
CVE-2022-31161CRITICAL9.8Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system comm...
CVE-2022-30634HIGH7.5Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite h...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now