2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29005 | MEDIUM | 6.1 | 2.5% | May 23, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate ... |
| CVE-2022-29004 | MEDIUM | 6.1 | 3.5% | May 23, 2022 | Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter... |
| CVE-2022-28932 | CRITICAL | 9.8 | 3.1% | May 23, 2022 | D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. |
| CVE-2022-1811 | MEDIUM | 5.4 | 0.7% | May 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9. |
| CVE-2022-28998 | HIGH | 8.1 | 2.1% | May 23, 2022 | Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive inf... |
| CVE-2022-28997 | HIGH | 7.5 | 1.9% | May 23, 2022 | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive ... |
| CVE-2022-0900 | MEDIUM | 5.4 | 0.4% | May 23, 2022 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NetDataSoft DivvyD... |
| CVE-2022-1817 | MEDIUM | 5.4 | 0.5% | May 23, 2022 | A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the ... |
| CVE-2022-1816 | MEDIUM | 5.4 | 0.5% | May 23, 2022 | A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issu... |
| CVE-2022-1810 | MEDIUM | 4.3 | 0.8% | May 23, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9. |
| CVE-2022-29599 | CRITICAL | 9.8 | 4.0% | May 23, 2022 | In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without ... |
| CVE-2022-28874 | HIGH | 7.5 | 0.6% | May 23, 2022 | Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products whil... |
| CVE-2022-1825 | MEDIUM | 5.4 | 0.6% | May 23, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8. |
| CVE-2022-1558 | MEDIUM | 4.8 | 1.0% | May 23, 2022 | The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2022-1547 | MEDIUM | 6.1 | 0.8% | May 23, 2022 | The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2022-1320 | MEDIUM | 4.8 | 1.0% | May 23, 2022 | The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could... |
| CVE-2022-1298 | MEDIUM | 4.8 | 0.6% | May 23, 2022 | The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged ... |
| CVE-2022-1268 | MEDIUM | 6.1 | 0.8% | May 23, 2022 | The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2022-1221 | MEDIUM | 6.1 | 2.0% | May 23, 2022 | The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputti... |
| CVE-2022-1218 | MEDIUM | 6.1 | 0.8% | May 23, 2022 | The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2022-1192 | MEDIUM | 6.1 | 3.0% | May 23, 2022 | The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting... |
| CVE-2022-1093 | MEDIUM | 4.8 | 0.6% | May 23, 2022 | The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it ... |
| CVE-2022-1014 | CRITICAL | 9.8 | 1.6% | May 23, 2022 | The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b... |
| CVE-2022-0781 | CRITICAL | 9.8 | 12.4% | May 23, 2022 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state... |
| CVE-2022-0346 | MEDIUM | 6.1 | 2.2% | May 23, 2022 | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now