2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28613HIGH7.5A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus T...
CVE-2022-26326MEDIUM6.1Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
CVE-2022-26325MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
CVE-2022-1515MEDIUM5.5A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This is...
CVE-2022-1475MEDIUM5.5An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavco...
CVE-2022-1378CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p...
CVE-2022-1377CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_r...
CVE-2022-1376CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p...
CVE-2022-1375CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_s...
CVE-2022-1374CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_u...
CVE-2022-1372CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog...
CVE-2022-1371CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe...
CVE-2022-1370CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRE...
CVE-2022-1369CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe...
CVE-2022-1367CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle...
CVE-2022-1366CRITICAL9.8Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle...
CVE-2022-1282MEDIUM6.1The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, whi...
CVE-2022-1281CRITICAL9.8The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is a...
CVE-2022-1273HIGH7.2The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege u...
CVE-2022-1269MEDIUM6.1The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in a...
CVE-2022-1255MEDIUM4.8The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV da...
CVE-2022-1250MEDIUM6.1The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirm...
CVE-2022-1239HIGH8.8The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could...
CVE-2022-1046MEDIUM4.8The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c...
CVE-2022-0952HIGH8.8The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now