2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31001HIGH7.5Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker c...
CVE-2022-31002HIGH7.5Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker c...
CVE-2022-29258MEDIUM6.1XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stre...
CVE-2022-29245MEDIUM5.9SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, th...
CVE-2022-29243MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2....
CVE-2022-29220MEDIUM6.5github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior...
CVE-2022-22361MEDIUM6.5IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3...
CVE-2022-23082HIGH7.5In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to san...
CVE-2022-30973MEDIUM5.5We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular express...
CVE-2022-1942HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-1926MEDIUM4.9Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1934HIGH7.8Use After Free in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-1931HIGH8.1Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1646MEDIUM4.8The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul...
CVE-2022-1645MEDIUM4.8The Amazon Link WordPress plugin through 3.2.10 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-1644MEDIUM4.8The Call&Book Mobile Bar WordPress plugin through 1.2.2 does not sanitize and escape some of its settings, which could a...
CVE-2022-1643MEDIUM4.8The Birthdays Widget WordPress plugin through 1.7.18 does not sanitise and escape some of its fields, which could allow ...
CVE-2022-1611HIGH8.8The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks...
CVE-2022-1589HIGH7.5The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CS...
CVE-2022-1583MEDIUM6.5The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" w...
CVE-2022-1582MEDIUM6.1The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to...
CVE-2022-1568MEDIUM4.8The Team Members WordPress plugin before 5.1.1 does not escape some of its Team settings, which could allow high privile...
CVE-2022-1566MEDIUM4.8The Quotes llama WordPress plugin before 1.0.0 does not sanitise and escape Quotes, which could allow high privilege use...
CVE-2022-1564MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which cou...
CVE-2022-1562MEDIUM5.4The Enable SVG WordPress plugin before 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now