2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1392 | HIGH | 7.5 | 11.1% | Apr 25, 2022 | The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include state... |
| CVE-2022-1391 | CRITICAL | 9.8 | 13.6% | Apr 25, 2022 | The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in requ... |
| CVE-2022-1390 | CRITICAL | 9.8 | 22.1% | Apr 25, 2022 | The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which... |
| CVE-2022-1228 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Opensea WordPress plugin before 1.0.3 does not sanitize and escape some of its settings, like its "Referer address" ... |
| CVE-2022-1156 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Books & Papers WordPress plugin through 0.20210223 does not escape its Custom DB prefix settings, allowing high priv... |
| CVE-2022-1153 | MEDIUM | 4.8 | 2.7% | Apr 25, 2022 | The LayerSlider WordPress plugin before 7.1.2 does not sanitise and escape Project's slug before outputting it back in v... |
| CVE-2022-1152 | MEDIUM | 5.4 | 0.6% | Apr 25, 2022 | The Menubar WordPress plugin before 5.8 does not sanitise and escape the command parameter before outputting it back in ... |
| CVE-2022-1094 | MEDIUM | 4.8 | 0.7% | Apr 25, 2022 | The amr users WordPress plugin before 4.59.4 does not sanitise and escape some of its settings, which could allow high p... |
| CVE-2022-1092 | MEDIUM | 4.3 | 0.4% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export... |
| CVE-2022-1027 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Page Restriction WordPress (WP) WordPress plugin before 1.2.7 allows bad actors with administrator privileges to the... |
| CVE-2022-0953 | MEDIUM | 6.1 | 2.7% | Apr 25, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUER... |
| CVE-2022-0876 | MEDIUM | 4.8 | 0.6% | Apr 25, 2022 | The Social comments by WpDevArt WordPress plugin before 2.5.0 does not sanitise and escape its settings, allowing high p... |
| CVE-2022-0782 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in... |
| CVE-2022-0769 | CRITICAL | 9.8 | 8.4% | Apr 25, 2022 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it... |
| CVE-2022-0693 | CRITICAL | 9.8 | 7.2% | Apr 25, 2022 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_... |
| CVE-2022-0657 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat... |
| CVE-2022-0656 | HIGH | 7.5 | 7.7% | Apr 25, 2022 | The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url... |
| CVE-2022-0634 | MEDIUM | 4.3 | 0.3% | Apr 25, 2022 | The ThirstyAffiliates WordPress plugin before 3.10.5 lacks authorization checks in the ta_insert_external_image action, ... |
| CVE-2022-0541 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a... |
| CVE-2022-0398 | MEDIUM | 5.4 | 0.3% | Apr 25, 2022 | The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 does not have authorisation and CSRF checks ... |
| CVE-2022-0363 | MEDIUM | 4.3 | 0.3% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-ex... |
| CVE-2022-0287 | MEDIUM | 4.3 | 0.8% | Apr 25, 2022 | The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX... |
| CVE-2022-29078 | CRITICAL | 9.8 | 32.4% | Apr 25, 2022 | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[... |
| CVE-2022-28094 | MEDIUM | 6.1 | 0.9% | Apr 25, 2022 | SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability vi... |
| CVE-2022-28093 | CRITICAL | 9.8 | 2.8% | Apr 25, 2022 | SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which al... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now