2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29005MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the component /obcs/user/profile.php of Online Birth Certificate ...
CVE-2022-29004MEDIUM6.1Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter...
CVE-2022-28932CRITICAL9.8D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.
CVE-2022-1811MEDIUM5.4Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.
CVE-2022-28998HIGH8.1Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive inf...
CVE-2022-28997HIGH7.5CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive ...
CVE-2022-0900MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NetDataSoft DivvyD...
CVE-2022-1817MEDIUM5.4A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the ...
CVE-2022-1816MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Zoo Management System 1.0. Affected by this issu...
CVE-2022-1810MEDIUM4.3Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.
CVE-2022-29599CRITICAL9.8In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without ...
CVE-2022-28874HIGH7.5Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products whil...
CVE-2022-1825MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository collectiveaccess/providence prior to 1.8.
CVE-2022-1558MEDIUM4.8The Curtain WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2022-1547MEDIUM6.1The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back i...
CVE-2022-1320MEDIUM4.8The Sliderby10Web WordPress plugin before 1.2.52 does not properly sanitize and escape some of its settings, which could...
CVE-2022-1298MEDIUM4.8The Tabs WordPress plugin before 2.2.8 does not sanitise and escape Tab descriptions, which could allow high privileged ...
CVE-2022-1268MEDIUM6.1The Donate Extra WordPress plugin through 2.02 does not sanitise and escape a parameter before outputting it back in the...
CVE-2022-1221MEDIUM6.1The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputti...
CVE-2022-1218MEDIUM6.1The Domain Replace WordPress plugin through 1.3.8 does not sanitise and escape a parameter before outputting it back in ...
CVE-2022-1192MEDIUM6.1The Turn off all comments WordPress plugin through 1.0 does not sanitise and escape the rows parameter before outputting...
CVE-2022-1093MEDIUM4.8The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it ...
CVE-2022-1014CRITICAL9.8The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b...
CVE-2022-0781CRITICAL9.8The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state...
CVE-2022-0346MEDIUM6.1The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now