2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1393 | MEDIUM | 5.4 | 0.6% | May 16, 2022 | The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subti... |
| CVE-2022-1386 | CRITICAL | 9.8 | 71.7% | May 16, 2022 | The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms wh... |
| CVE-2022-1349 | MEDIUM | 4.3 | 0.6% | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid... |
| CVE-2022-1334 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which ... |
| CVE-2022-1267 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting i... |
| CVE-2022-1265 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which co... |
| CVE-2022-1217 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable befo... |
| CVE-2022-1216 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before ou... |
| CVE-2022-1182 | HIGH | 8.8 | 1.3% | May 16, 2022 | The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using... |
| CVE-2022-1103 | HIGH | 8.8 | 14.3% | May 16, 2022 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi... |
| CVE-2022-1089 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, whic... |
| CVE-2022-1062 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2022-1051 | MEDIUM | 5.4 | 1.2% | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanit... |
| CVE-2022-0873 | MEDIUM | 4.8 | 0.9% | May 16, 2022 | The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting ... |
| CVE-2022-0867 | CRITICAL | 9.8 | 11.3% | May 16, 2022 | The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it ... |
| CVE-2022-0578 | MEDIUM | 6.5 | 0.8% | May 16, 2022 | Code Injection in GitHub repository publify/publify prior to 9.2.8. |
| CVE-2022-0574 | MEDIUM | 6.5 | 0.8% | May 16, 2022 | Improper Access Control in GitHub repository publify/publify prior to 9.2.8. |
| CVE-2022-0573 | HIGH | 8.8 | 1.9% | May 16, 2022 | JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead ... |
| CVE-2022-30777 | MEDIUM | 6.1 | 2.1% | May 16, 2022 | Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter. |
| CVE-2022-30776 | MEDIUM | 6.1 | 4.0% | May 16, 2022 | atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter. |
| CVE-2022-30013 | MEDIUM | 5.4 | 0.6% | May 16, 2022 | A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execut... |
| CVE-2022-29623 | HIGH | 7.8 | 1.2% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to... |
| CVE-2022-29622 | CRITICAL | 9.8 | 3.2% | May 16, 2022 | An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted fil... |
| CVE-2022-29354 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrar... |
| CVE-2022-29353 | CRITICAL | 9.8 | 1.6% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now