2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1772 | MEDIUM | 4.8 | 0.7% | Jun 13, 2022 | The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is re... |
| CVE-2022-1765 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache image... |
| CVE-2022-1764 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2022-1763 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows c... |
| CVE-2022-1762 | HIGH | 7.5 | 1.2% | Jun 13, 2022 | The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origi... |
| CVE-2022-1761 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. This... |
| CVE-2022-1759 | MEDIUM | 5.4 | 0.3% | Jun 13, 2022 | The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic... |
| CVE-2022-1758 | HIGH | 8.8 | 0.6% | Jun 13, 2022 | The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settin... |
| CVE-2022-1756 | MEDIUM | 6.1 | 1.8% | Jun 13, 2022 | The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it ... |
| CVE-2022-1724 | MEDIUM | 6.1 | 1.7% | Jun 13, 2022 | The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting t... |
| CVE-2022-1710 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fiel... |
| CVE-2022-1707 | MEDIUM | 6.1 | 88.6% | Jun 13, 2022 | The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s para... |
| CVE-2022-1694 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page... |
| CVE-2022-1656 | MEDIUM | 5.4 | 0.5% | Jun 13, 2022 | Vulnerable versions of the JupiterX Theme (<=2.0.6) allow any logged-in user, including subscriber-level users, to acces... |
| CVE-2022-1624 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Latest Tweets Widget WordPress plugin through 1.1.4 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1612 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which c... |
| CVE-2022-1608 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, ... |
| CVE-2022-1605 | MEDIUM | 6.5 | 0.5% | Jun 13, 2022 | The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could... |
| CVE-2022-1604 | MEDIUM | 6.1 | 0.8% | Jun 13, 2022 | The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2022-1595 | MEDIUM | 5.3 | 2.6% | Jun 13, 2022 | The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque... |
| CVE-2022-1594 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | The HC Custom WP-Admin URL WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, wh... |
| CVE-2022-1549 | MEDIUM | 5.4 | 0.6% | Jun 13, 2022 | The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor do... |
| CVE-2022-1532 | MEDIUM | 6.1 | 0.8% | Jun 13, 2022 | Themify WordPress plugin before 1.3.8 does not sanitise and escape the page parameter before outputting it back in an at... |
| CVE-2022-1412 | HIGH | 7.5 | 1.4% | Jun 13, 2022 | The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen... |
| CVE-2022-1336 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Carousel CK WordPress plugin through 1.1.0 does not sanitize and escape Slide's descriptions, which could allow high... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now