2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31075MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2022-31140CRITICAL9.1Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12...
CVE-2022-31074MEDIUM6.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2022-31073HIGH7.5KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2022-31139HIGH7.5UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a nam...
CVE-2022-31138HIGH8.8mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be ...
CVE-2022-2123MEDIUM4.3The WP Opt-in WordPress plugin through 1.4.1 is vulnerable to CSRF which allows changed plugin settings and can be used ...
CVE-2022-2093MEDIUM4.8The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow h...
CVE-2022-2092MEDIUM6.1The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting pa...
CVE-2022-2091MEDIUM6.5The Cache Images WordPress plugin before 3.2.1 does not implement nonce checks, which could allow attackers to make any ...
CVE-2022-2089MEDIUM4.8The Bold Page Builder WordPress plugin before 4.3.3 does not sanitise and escape some of its settings, which could allow...
CVE-2022-2050MEDIUM4.8The WP-Paginate WordPress plugin before 2.1.9 does not escape one of its settings, which could allow high privilege user...
CVE-2022-1957MEDIUM4.3The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co...
CVE-2022-1956MEDIUM4.3The Shortcut Macros WordPress plugin through 1.3 does not have authorisation and CSRF checks in place when updating its ...
CVE-2022-1952CRITICAL9.8The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient i...
CVE-2022-1951MEDIUM6.1The core plugin for kitestudio WordPress plugin before 2.3.1 does not sanitise and escape some parameters before outputt...
CVE-2022-1938MEDIUM5.4The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a header when processing request to generate...
CVE-2022-1937MEDIUM6.1The Awin Data Feed WordPress plugin before 1.8 does not sanitise and escape a parameter before outputting it back via an...
CVE-2022-1910MEDIUM6.1The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter befor...
CVE-2022-1894MEDIUM4.8The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high priv...
CVE-2022-1757MEDIUM5.4The pagebar WordPress plugin before 2.70 does not have CSRF check in place when updating its settings, which could allow...
CVE-2022-1732MEDIUM6.5The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login ...
CVE-2022-1626MEDIUM5.4The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could al...
CVE-2022-1599MEDIUM6.5The Admin Management Xtended WordPress plugin before 2.4.5 does not have CSRF checks in some of its AJAX actions, allowi...
CVE-2022-1576MEDIUM6.5The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users l...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now