2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1393MEDIUM5.4The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subti...
CVE-2022-1386CRITICAL9.8The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms wh...
CVE-2022-1349MEDIUM4.3The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid...
CVE-2022-1334MEDIUM4.8The WP YouTube Live WordPress plugin before 1.8.3 does not validate, sanitise and escape various of its settings, which ...
CVE-2022-1267MEDIUM6.1The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting i...
CVE-2022-1265MEDIUM4.8The BulletProof Security WordPress plugin before 6.1 does not sanitize and escape some of its CAPTCHA settings, which co...
CVE-2022-1217MEDIUM6.1The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable befo...
CVE-2022-1216MEDIUM6.1The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before ou...
CVE-2022-1182HIGH8.8The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using...
CVE-2022-1103HIGH8.8The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi...
CVE-2022-1089MEDIUM4.8The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, whic...
CVE-2022-1062MEDIUM4.8The th23 Social WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow high...
CVE-2022-1051MEDIUM5.4The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanit...
CVE-2022-0873MEDIUM4.8The Gmedia Photo Gallery WordPress plugin before 1.20.0 does not sanitise and escape the Album's name before outputting ...
CVE-2022-0867CRITICAL9.8The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it ...
CVE-2022-0578MEDIUM6.5Code Injection in GitHub repository publify/publify prior to 9.2.8.
CVE-2022-0574MEDIUM6.5Improper Access Control in GitHub repository publify/publify prior to 9.2.8.
CVE-2022-0573HIGH8.8JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead ...
CVE-2022-30777MEDIUM6.1Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
CVE-2022-30776MEDIUM6.1atmail 6.5.0 allows XSS via the index.php/admin/index/ error parameter.
CVE-2022-30013MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the upload function of totaljs CMS 3.4.5 allows attackers to execut...
CVE-2022-29623HIGH7.8An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to...
CVE-2022-29622CRITICAL9.8An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted fil...
CVE-2022-29354CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrar...
CVE-2022-29353CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now