2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1556CRITICAL9.8The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL s...
CVE-2022-1542MEDIUM4.8The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-1528MEDIUM6.1The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting i...
CVE-2022-1527MEDIUM6.1The WP 2FA WordPress plugin before 2.2.1 does not sanitise and escape a parameter before outputting it back in an admin ...
CVE-2022-1456MEDIUM4.8The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privileg...
CVE-2022-1395MEDIUM4.8The Easy FAQ with Expanding Text WordPress plugin through 3.2.8.3.1 does not sanitise and escape its settings, allowing ...
CVE-2022-1387MEDIUM4.8The No Future Posts WordPress plugin through 1.4 does not escape its settings, which could allow high privilege users su...
CVE-2022-1299MEDIUM4.8The Slideshow WordPress plugin through 2.3.1 does not sanitize and escape some of its default slideshow settings, which ...
CVE-2022-1294MEDIUM4.8The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high...
CVE-2022-1275MEDIUM4.8The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged...
CVE-2022-1203MEDIUM4.3The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as...
CVE-2022-1009MEDIUM6.1The Smush WordPress plugin before 3.9.9 does not sanitise and escape a configuration parameter before outputting it back...
CVE-2022-0642MEDIUM5.4The JivoChat Live Chat WordPress plugin before 1.3.5.4 does not properly check CSRF tokens on POST requests to the plugi...
CVE-2022-0376MEDIUM4.8The User Meta WordPress plugin before 2.4.3 does not sanitise and escape the Form Name, as well as Shared Field Labels b...
CVE-2022-1928MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
CVE-2022-1927HIGH7.8Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVE-2022-25878HIGH7.5The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify pro...
CVE-2022-1897HIGH7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2022-20807MEDIUM6.5Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc...
CVE-2022-20806HIGH7.1Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc...
CVE-2022-20802MEDIUM5.4A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attac...
CVE-2022-20797CRITICAL9.1A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Ent...
CVE-2022-20765MEDIUM4.8A vulnerability in the web applications of Cisco UCS Director could allow an authenticated, remote attacker to conduct a...
CVE-2022-20674MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa...
CVE-2022-20673MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Softwa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now