2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1654 | HIGH | 8.8 | 1.5% | Jun 13, 2022 | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or cu... |
| CVE-2022-0209 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Mitsol Social Post Feed WordPress plugin before 1.11 does not escape some of its settings before outputting them bac... |
| CVE-2022-31400 | MEDIUM | 4.8 | 0.5% | Jun 13, 2022 | A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execu... |
| CVE-2022-31398 | MEDIUM | 4.8 | 0.5% | Jun 13, 2022 | A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute... |
| CVE-2022-31041 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the for... |
| CVE-2022-2067 | CRITICAL | 9.1 | 1.8% | Jun 13, 2022 | SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0. |
| CVE-2022-2066 | MEDIUM | 6.1 | 0.9% | Jun 13, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.06. |
| CVE-2022-2065 | MEDIUM | 5.4 | 0.6% | Jun 13, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository neorazorx/facturascripts prior to 2022.06. |
| CVE-2022-1985 | MEDIUM | 6.1 | 1.1% | Jun 13, 2022 | The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and includi... |
| CVE-2022-1918 | HIGH | 8.8 | 0.8% | Jun 13, 2022 | The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2022-1900 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. Thi... |
| CVE-2022-1822 | MEDIUM | 6.1 | 1.0% | Jun 13, 2022 | The Zephyr Project Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘project’ parame... |
| CVE-2022-1814 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The WP Admin Style WordPress plugin through 0.1.2 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2022-1800 | HIGH | 7.2 | 1.2% | Jun 13, 2022 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp... |
| CVE-2022-1793 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow a... |
| CVE-2022-1792 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-1791 | HIGH | 8.1 | 0.5% | Jun 13, 2022 | The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its setting... |
| CVE-2022-1790 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, w... |
| CVE-2022-1788 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks.... |
| CVE-2022-1787 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allo... |
| CVE-2022-1781 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The postTabs WordPress plugin through 2.10.6 does not have CSRF check in place when updating its settings, which could a... |
| CVE-2022-1780 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The LaTeX for WordPress plugin through 3.4.10 does not have CSRF check in place when updating its settings, which could ... |
| CVE-2022-1779 | HIGH | 8.1 | 0.5% | Jun 13, 2022 | The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which... |
| CVE-2022-1777 | HIGH | 8.8 | 1.2% | Jun 13, 2022 | The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to ... |
| CVE-2022-1773 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | The WP Athletics WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting back in an ad... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now