2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1335 | MEDIUM | 4.8 | 0.6% | Jun 13, 2022 | The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig... |
| CVE-2022-1208 | MEDIUM | 5.4 | 0.9% | Jun 13, 2022 | The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured o... |
| CVE-2022-1202 | HIGH | 7.8 | 1.0% | Jun 13, 2022 | The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea... |
| CVE-2022-0885 | CRITICAL | 9.8 | 9.1% | Jun 13, 2022 | The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter... |
| CVE-2022-0863 | HIGH | 7.2 | 22.4% | Jun 13, 2022 | The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high ... |
| CVE-2022-0827 | CRITICAL | 9.8 | 9.0% | Jun 13, 2022 | The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta... |
| CVE-2022-0786 | CRITICAL | 9.8 | 11.2% | Jun 13, 2022 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme... |
| CVE-2022-0745 | MEDIUM | 6.5 | 0.8% | Jun 13, 2022 | The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e... |
| CVE-2022-0626 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting t... |
| CVE-2022-31040 | MEDIUM | 6.1 | 0.7% | Jun 13, 2022 | Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie cons... |
| CVE-2022-2064 | HIGH | 8.8 | 1.1% | Jun 13, 2022 | Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-2063 | HIGH | 8.8 | 1.3% | Jun 13, 2022 | Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-2062 | HIGH | 7.5 | 1.5% | Jun 13, 2022 | Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+. |
| CVE-2022-2061 | LOW | 3.3 | 0.4% | Jun 13, 2022 | Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0. |
| CVE-2022-2060 | MEDIUM | 5.4 | 0.8% | Jun 13, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0. |
| CVE-2022-32741 | MEDIUM | 5.3 | 0.8% | Jun 13, 2022 | Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based... |
| CVE-2022-32740 | MEDIUM | 5.3 | 0.7% | Jun 13, 2022 | A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome... |
| CVE-2022-32739 | MEDIUM | 5.3 | 0.7% | Jun 13, 2022 | When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received... |
| CVE-2022-29894 | MEDIUM | 4.8 | 0.7% | Jun 13, 2022 | Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By explo... |
| CVE-2022-29525 | CRITICAL | 9.8 | 1.4% | Jun 13, 2022 | Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated at... |
| CVE-2022-28704 | HIGH | 7.2 | 2.4% | Jun 13, 2022 | Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log... |
| CVE-2022-27231 | MEDIUM | 6.1 | 1.0% | Jun 13, 2022 | Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl... |
| CVE-2022-27174 | MEDIUM | 4.3 | 0.4% | Jun 13, 2022 | Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthen... |
| CVE-2022-26834 | HIGH | 7.5 | 1.4% | Jun 13, 2022 | Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obt... |
| CVE-2022-26041 | MEDIUM | 6.5 | 1.4% | Jun 13, 2022 | Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrativ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now