2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1546MEDIUM6.1The WooCommerce - Product Importer WordPress plugin through 1.5.2 does not sanitise and escape the imported data before ...
CVE-2022-1474MEDIUM6.1The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in...
CVE-2022-1220MEDIUM6.1The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admi...
CVE-2022-1057CRITICAL9.8The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter be...
CVE-2022-30792HIGH7.5In CmpChannelServer of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized atta...
CVE-2022-30791HIGH7.5In CmpBlkDrvTcp of CODESYS V3 in multiple versions an uncontrolled ressource consumption allows an unauthorized attacker...
CVE-2022-2302CRITICAL9.8Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been lo...
CVE-2022-1794MEDIUM5.5The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is vi...
CVE-2022-29926Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-2368CRITICAL9.8Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
CVE-2022-35416MEDIUM6.1H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.
CVE-2022-32294CRITICAL9.8Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ...
CVE-2022-35414HIGH8.8softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_r...
CVE-2022-31588CRITICAL9.3The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_f...
CVE-2022-31587CRITICAL9.3The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Fl...
CVE-2022-31586CRITICAL9.3The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because t...
CVE-2022-31585CRITICAL9.3The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Fla...
CVE-2022-31584CRITICAL9.3The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_fil...
CVE-2022-31583CRITICAL9.3The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because t...
CVE-2022-31582CRITICAL9.3The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_fi...
CVE-2022-31581CRITICAL9.3The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file fu...
CVE-2022-31580CRITICAL9.3The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flas...
CVE-2022-31579CRITICAL9.3The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_fil...
CVE-2022-31578HIGH7.5The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_fi...
CVE-2022-31577CRITICAL9.3The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the F...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now