2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1914 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could... |
| CVE-2022-1913 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2022-1904 | MEDIUM | 6.1 | 1.4% | Jun 27, 2022 | The Pricing Tables WordPress Plugin WordPress plugin before 3.2.1 does not sanitise and escape parameter before outputti... |
| CVE-2022-1903 | HIGH | 8.1 | 8.5% | Jun 27, 2022 | The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing non... |
| CVE-2022-1885 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Cimy Header Image Rotator WordPress plugin through 6.1.1 does not have CSRF check in place when updating its setting... |
| CVE-2022-1847 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Rotating Posts WordPress plugin through 1.11 does not have CSRF check in place when updating its settings, which cou... |
| CVE-2022-1846 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-1845 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The WP Post Styling WordPress plugin before 1.3.1 does not have CSRF checks in various actions, which could allow attack... |
| CVE-2022-1844 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The WP Sentry WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could all... |
| CVE-2022-1843 | MEDIUM | 6.5 | 0.5% | Jun 27, 2022 | The MailPress WordPress plugin through 7.2.1 does not have CSRF checks in various places, which could allow attackers to... |
| CVE-2022-1842 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, whic... |
| CVE-2022-1776 | MEDIUM | 5.4 | 0.6% | Jun 27, 2022 | The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape so... |
| CVE-2022-1653 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints ... |
| CVE-2022-1627 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The My Private Site WordPress plugin before 3.0.8 does not have CSRF check in place when updating its settings, which co... |
| CVE-2022-1625 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The New User Approve WordPress plugin before 2.4 does not have CSRF check in place when updating its settings and adding... |
| CVE-2022-1593 | MEDIUM | 6.1 | 0.7% | Jun 27, 2022 | The Site Offline or Coming Soon WordPress plugin through 1.6.6 does not have CSRF check in place when updating its setti... |
| CVE-2022-1574 | CRITICAL | 9.8 | 11.9% | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does no... |
| CVE-2022-1573 | MEDIUM | 4.3 | 0.4% | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could all... |
| CVE-2022-1572 | HIGH | 8.1 | 0.5% | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to a... |
| CVE-2022-1470 | MEDIUM | 6.1 | 0.7% | Jun 27, 2022 | The Ultimate WooCommerce CSV Importer WordPress plugin through 2.0 does not sanitise and escape the imported data before... |
| CVE-2022-1327 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Image Gallery WordPress plugin before 1.1.6 does not sanitize and escape some of its Image fields, which could allow... |
| CVE-2022-1326 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Form - Contact Form WordPress plugin through 1.2.0 does not sanitize and escape Custom text fields, which could allo... |
| CVE-2022-1321 | MEDIUM | 4.8 | 0.5% | Jun 27, 2022 | The miniOrange's Google Authenticator WordPress plugin before 5.5.6 does not sanitise and escape some of its settings, l... |
| CVE-2022-1113 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which... |
| CVE-2022-1095 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | The Mihdan: No External Links WordPress plugin before 5.0.2 does not sanitise and escape some of its settings, which cou... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now