2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1720HIGH7.8Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capabl...
CVE-2022-25772MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers ...
CVE-2022-1945MEDIUM4.8The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings...
CVE-2022-1939HIGH7.2The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil...
CVE-2022-1915MEDIUM4.8The WP Zillow Review Slider WordPress plugin before 2.4 does not escape a settings, which could allow high privilege use...
CVE-2022-1905CRITICAL9.8The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in...
CVE-2022-1896MEDIUM4.8The underConstruction WordPress plugin before 1.21 does not sanitise or escape the "Display a custom page using your own...
CVE-2022-1895MEDIUM4.3The underConstruction WordPress plugin before 1.20 does not have CSRF check in place when deactivating the construction ...
CVE-2022-1889MEDIUM4.8The Newsletter WordPress plugin before 7.4.6 does not escape and sanitise the preheader_text setting, which could allow ...
CVE-2022-1832MEDIUM6.5The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co...
CVE-2022-1831MEDIUM6.5The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allo...
CVE-2022-1830MEDIUM6.5The Amazon Einzeltitellinks WordPress plugin through 1.3.3 does not have CSRF check in place when updating its settings,...
CVE-2022-1829MEDIUM6.5The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which...
CVE-2022-1828MEDIUM6.5The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, w...
CVE-2022-1827MEDIUM6.5The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, wh...
CVE-2022-1826MEDIUM6.5The Cross-Linker WordPress plugin through 3.0.1.9 does not have CSRF check in place when creating Cross-Links, which cou...
CVE-2022-1824HIGH8.2An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow ...
CVE-2022-1823HIGH7.8Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allo...
CVE-2022-1818MEDIUM5.4The Multi-page Toolkit WordPress plugin through 2.6 does not have CSRF check in place when updating its settings, which ...
CVE-2022-1801HIGH7.5The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact fo...
CVE-2022-1717MEDIUM4.8The Custom Share Buttons with Floating Sidebar WordPress plugin before 4.2 does not sanitise and escape some of its sett...
CVE-2022-1630MEDIUM6.5The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing ...
CVE-2022-1614HIGH7.5The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO...
CVE-2022-1610MEDIUM6.5The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which...
CVE-2022-1603MEDIUM4.3The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now