2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1335MEDIUM4.8The Slideshow CK WordPress plugin before 1.4.10 does not sanitize and escape Slide's descriptions, which could allow hig...
CVE-2022-1208MEDIUM5.4The Ultimate Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Biography field featured o...
CVE-2022-1202HIGH7.8The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea...
CVE-2022-0885CRITICAL9.8The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter...
CVE-2022-0863HIGH7.2The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high ...
CVE-2022-0827CRITICAL9.8The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta...
CVE-2022-0786CRITICAL9.8The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme...
CVE-2022-0745MEDIUM6.5The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e...
CVE-2022-0626MEDIUM6.1The Advanced Admin Search WordPress plugin before 1.1.6 does not sanitize and escape some parameters before outputting t...
CVE-2022-31040MEDIUM6.1Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie cons...
CVE-2022-2064HIGH8.8Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2063HIGH8.8Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2062HIGH7.5Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.
CVE-2022-2061LOW3.3Heap-based Buffer Overflow in GitHub repository hpjansson/chafa prior to 1.12.0.
CVE-2022-2060MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-32741MEDIUM5.3Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based...
CVE-2022-32740MEDIUM5.3A reply to a forwarded email article by a 3rd party could unintensionally expose the email content to the ticket custome...
CVE-2022-32739MEDIUM5.3When Secure::DisableBanner system configuration has been disabled and agent shares his calendar via public URL, received...
CVE-2022-29894MEDIUM4.8Strapi v3.x.x versions and earlier contain a stored cross-site scripting vulnerability in file upload function. By explo...
CVE-2022-29525CRITICAL9.8Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated at...
CVE-2022-28704HIGH7.2Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log...
CVE-2022-27231MEDIUM6.1Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl...
CVE-2022-27174MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthen...
CVE-2022-26834HIGH7.5Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obt...
CVE-2022-26041MEDIUM6.5Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrativ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now