2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0783CRITICAL9.8The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous par...
CVE-2022-0773CRITICAL9.8The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in...
CVE-2022-0771CRITICAL9.8The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before usi...
CVE-2022-0662MEDIUM4.8The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u...
CVE-2022-0649MEDIUM4.8The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo...
CVE-2022-0428MEDIUM6.1The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in ...
CVE-2022-0418MEDIUM4.8The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege ...
CVE-2022-0191MEDIUM6.5The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic...
CVE-2022-28573CRITICAL9.8D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting...
CVE-2022-28056CRITICAL9.8ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/...
CVE-2022-28054CRITICAL9.8Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execut...
CVE-2022-27983HIGH7.5RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url par...
CVE-2022-27982CRITICAL9.8RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the ...
CVE-2022-27466CRITICAL9.8MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
CVE-2022-28572HIGH8.8Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
CVE-2022-28571CRITICAL9.8D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.
CVE-2022-23065MEDIUM5.4In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog pe...
CVE-2022-23064HIGH8.8In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host ...
CVE-2022-29973MEDIUM4.7relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in cert...
CVE-2022-23904HIGH8Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated us...
CVE-2022-1300CRITICAL9.8Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of thi...
CVE-2022-29970HIGH7.5Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
CVE-2022-29969MEDIUM6.1The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist an...
CVE-2022-29968HIGH7.8An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kio...
CVE-2022-29849HIGH7.8In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now