2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1720 | HIGH | 7.8 | 2.1% | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capabl... |
| CVE-2022-25772 | MEDIUM | 6.1 | 61.2% | Jun 20, 2022 | A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers ... |
| CVE-2022-1945 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings... |
| CVE-2022-1939 | HIGH | 7.2 | 1.4% | Jun 20, 2022 | The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil... |
| CVE-2022-1915 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use... |
| CVE-2022-1905 | CRITICAL | 9.8 | 36.7% | Jun 20, 2022 | The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in... |
| CVE-2022-1896 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own... |
| CVE-2022-1895 | MEDIUM | 4.3 | 0.4% | Jun 20, 2022 | The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction ... |
| CVE-2022-1889 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow ... |
| CVE-2022-1832 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co... |
| CVE-2022-1831 | MEDIUM | 6.5 | 0.4% | Jun 20, 2022 | The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-1830 | MEDIUM | 6.5 | 0.4% | Jun 20, 2022 | The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,... |
| CVE-2022-1829 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1828 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2022-1827 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1826 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou... |
| CVE-2022-1824 | HIGH | 8.2 | 0.3% | Jun 20, 2022 | An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow ... |
| CVE-2022-1823 | HIGH | 7.8 | 0.3% | Jun 20, 2022 | Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allo... |
| CVE-2022-1818 | MEDIUM | 5.4 | 0.3% | Jun 20, 2022 | The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which ... |
| CVE-2022-1801 | HIGH | 7.5 | 1.2% | Jun 20, 2022 | The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact fo... |
| CVE-2022-1717 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its sett... |
| CVE-2022-1630 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing ... |
| CVE-2022-1614 | HIGH | 7.5 | 1.1% | Jun 20, 2022 | The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO... |
| CVE-2022-1610 | MEDIUM | 6.5 | 0.5% | Jun 20, 2022 | The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1603 | MEDIUM | 4.3 | 0.4% | Jun 20, 2022 | The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now