2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30126MEDIUM5.5In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lea...
CVE-2022-30055CRITICAL9.8Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.
CVE-2022-30050MEDIUM6.1Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
CVE-2022-25169MEDIUM5.5The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on caref...
CVE-2022-30523HIGH7.8Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalat...
CVE-2022-1728MEDIUM6.5Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2...
CVE-2022-1726MEDIUM5.4Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repositor...
CVE-2022-1722LOW3.3SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5. SSRF to internal ...
CVE-2022-1721HIGH7.5Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web appli...
CVE-2022-1713HIGH7.5SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read...
CVE-2022-1560MEDIUM6.5The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an includ...
CVE-2022-1559MEDIUM4.8The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an at...
CVE-2022-1557MEDIUM5.4The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating...
CVE-2022-1553MEDIUM4.9Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to...
CVE-2022-1512MEDIUM4.8The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow hi...
CVE-2022-1465MEDIUM6.1The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before out...
CVE-2022-1455MEDIUM6.1The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute ...
CVE-2022-1436MEDIUM6.1The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number paramet...
CVE-2022-1435MEDIUM4.8The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could ...
CVE-2022-1425MEDIUM4.3The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid...
CVE-2022-1418MEDIUM6.1The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network s...
CVE-2022-1409HIGH7.2The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high...
CVE-2022-1408MEDIUM4.8The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputti...
CVE-2022-1407MEDIUM6.5The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a ...
CVE-2022-1398MEDIUM6.5The External Media without Import WordPress plugin through 1.1.2 does not have any authorisation and does to ensure that...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now