2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29972HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift...
CVE-2022-29971HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena O...
CVE-2022-29933HIGH8.8Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the a...
CVE-2022-28739HIGH7.5There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occu...
CVE-2022-28738CRITICAL9.8A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to ...
CVE-2022-27412CRITICAL9.8Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
CVE-2022-27308MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar...
CVE-2022-28162LOW3.3Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
CVE-2022-28161MEDIUM5.5An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allo...
CVE-2022-27114MEDIUM5.5There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and ...
CVE-2022-22481MEDIUM5.3IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web inter...
CVE-2022-22319MEDIUM5.4IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could ...
CVE-2022-1338MEDIUM4.8The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv...
CVE-2022-1303MEDIUM4.8The Slide Anything WordPress plugin before 2.3.44 does not sanitize and escape sliders' description, which could allow h...
CVE-2022-1171MEDIUM6.1The Vertical scroll recent post WordPress plugin before 14.0 does not sanitise and escape a parameter before outputting ...
CVE-2022-1104MEDIUM4.8The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allo...
CVE-2022-1047MEDIUM6.1The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL b...
CVE-2022-1013CRITICAL9.8The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be...
CVE-2022-0948CRITICAL9.8The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before us...
CVE-2022-0898MEDIUM5.4The IgniteUp WordPress plugin through 3.4.1 does not sanitise and escape some fields when high privilege users don't hav...
CVE-2022-0874MEDIUM4.8The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us...
CVE-2022-0836CRITICAL9.8The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL...
CVE-2022-0826CRITICAL9.8The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL st...
CVE-2022-0817CRITICAL9.8The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v...
CVE-2022-0814CRITICAL9.8The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now