2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0783 | CRITICAL | 9.8 | 6.7% | May 2, 2022 | The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous par... |
| CVE-2022-0773 | CRITICAL | 9.8 | 42.2% | May 2, 2022 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in... |
| CVE-2022-0771 | CRITICAL | 9.8 | 1.6% | May 2, 2022 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before usi... |
| CVE-2022-0662 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u... |
| CVE-2022-0649 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo... |
| CVE-2022-0428 | MEDIUM | 6.1 | 0.8% | May 2, 2022 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in ... |
| CVE-2022-0418 | MEDIUM | 4.8 | 0.6% | May 2, 2022 | The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege ... |
| CVE-2022-0191 | MEDIUM | 6.5 | 0.5% | May 2, 2022 | The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic... |
| CVE-2022-28573 | CRITICAL | 9.8 | 27.5% | May 2, 2022 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting... |
| CVE-2022-28056 | CRITICAL | 9.8 | 1.3% | May 2, 2022 | ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/... |
| CVE-2022-28054 | CRITICAL | 9.8 | 28.2% | May 2, 2022 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execut... |
| CVE-2022-27983 | HIGH | 7.5 | 0.9% | May 2, 2022 | RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url par... |
| CVE-2022-27982 | CRITICAL | 9.8 | 2.0% | May 2, 2022 | RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the ... |
| CVE-2022-27466 | CRITICAL | 9.8 | 1.6% | May 2, 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. |
| CVE-2022-28572 | HIGH | 8.8 | 2.6% | May 2, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function |
| CVE-2022-28571 | CRITICAL | 9.8 | 5.6% | May 2, 2022 | D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli. |
| CVE-2022-23065 | MEDIUM | 5.4 | 0.6% | May 2, 2022 | In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog pe... |
| CVE-2022-23064 | HIGH | 8.8 | 1.2% | May 2, 2022 | In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host ... |
| CVE-2022-29973 | MEDIUM | 4.7 | 0.3% | May 2, 2022 | relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in cert... |
| CVE-2022-23904 | HIGH | 8 | 0.4% | May 2, 2022 | Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated us... |
| CVE-2022-1300 | CRITICAL | 9.8 | 1.4% | May 2, 2022 | Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of thi... |
| CVE-2022-29970 | HIGH | 7.5 | 1.9% | May 2, 2022 | Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. |
| CVE-2022-29969 | MEDIUM | 6.1 | 0.7% | May 2, 2022 | The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist an... |
| CVE-2022-29968 | HIGH | 7.8 | 1.1% | May 2, 2022 | An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kio... |
| CVE-2022-29849 | HIGH | 7.8 | 0.3% | May 2, 2022 | In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were s... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now