2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1384HIGH8.8Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Mark...
CVE-2022-1329HIGH8.8The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t...
CVE-2022-1187MEDIUM6.1The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/ad...
CVE-2022-1186MEDIUM5.3The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visito...
CVE-2022-1119HIGH7.5The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/i...
CVE-2022-1019MEDIUM6.1Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability al...
CVE-2022-0993CRITICAL9.8The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to...
CVE-2022-0992CRITICAL9.8The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to...
CVE-2022-24825MEDIUM5.3Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent serve...
CVE-2022-27104CRITICAL9.8An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
CVE-2022-27055HIGH7.5ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When...
CVE-2022-25648CRITICAL9.8The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(rem...
CVE-2022-29153HIGH7.5HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C...
CVE-2022-29315HIGH8.8Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV fea...
CVE-2022-27927CRITICAL9.8A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application d...
CVE-2022-26595MEDIUM4.3Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user...
CVE-2022-26593MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through...
CVE-2022-0645MEDIUM6.1Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to...
CVE-2022-1065HIGH8.8A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentica...
CVE-2022-28108HIGH8.8Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-url...
CVE-2022-29464CRITICAL9.8Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file...
CVE-2022-24841HIGH8.1fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu...
CVE-2022-29458HIGH7.1ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_...
CVE-2022-29457HIGH8.8Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 ...
CVE-2022-24863HIGH7.5http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now