2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1384 | HIGH | 8.8 | 0.6% | Apr 19, 2022 | Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Mark... |
| CVE-2022-1329 | HIGH | 8.8 | 92.9% | Apr 19, 2022 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t... |
| CVE-2022-1187 | MEDIUM | 6.1 | 1.3% | Apr 19, 2022 | The WordPress WP YouTube Live Plugin is vulnerable to Reflected Cross-Site Scripting via POST data found in the ~/inc/ad... |
| CVE-2022-1186 | MEDIUM | 5.3 | 1.1% | Apr 19, 2022 | The WordPress plugin Be POPIA Compliant exposed sensitive information to unauthenticated users consisting of site visito... |
| CVE-2022-1119 | HIGH | 7.5 | 19.6% | Apr 19, 2022 | The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/i... |
| CVE-2022-1019 | MEDIUM | 6.1 | 0.6% | Apr 19, 2022 | Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability al... |
| CVE-2022-0993 | CRITICAL | 9.8 | 7.5% | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to... |
| CVE-2022-0992 | CRITICAL | 9.8 | 2.9% | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to... |
| CVE-2022-24825 | MEDIUM | 5.3 | 0.9% | Apr 19, 2022 | Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent serve... |
| CVE-2022-27104 | CRITICAL | 9.8 | 1.2% | Apr 19, 2022 | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. |
| CVE-2022-27055 | HIGH | 7.5 | 1.5% | Apr 19, 2022 | ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When... |
| CVE-2022-25648 | CRITICAL | 9.8 | 4.6% | Apr 19, 2022 | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(rem... |
| CVE-2022-29153 | HIGH | 7.5 | 8.5% | Apr 19, 2022 | HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C... |
| CVE-2022-29315 | HIGH | 8.8 | 1.4% | Apr 19, 2022 | Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV fea... |
| CVE-2022-27927 | CRITICAL | 9.8 | 13.6% | Apr 19, 2022 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application d... |
| CVE-2022-26595 | MEDIUM | 4.3 | 0.7% | Apr 19, 2022 | Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user... |
| CVE-2022-26593 | MEDIUM | 5.4 | 0.6% | Apr 19, 2022 | Cross-site scripting (XSS) vulnerability in the Asset module's asset categories selector in Liferay Portal 7.3.3 through... |
| CVE-2022-0645 | MEDIUM | 6.1 | 0.8% | Apr 19, 2022 | Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to... |
| CVE-2022-1065 | HIGH | 8.8 | 2.8% | Apr 19, 2022 | A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentica... |
| CVE-2022-28108 | HIGH | 8.8 | 11.8% | Apr 19, 2022 | Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-url... |
| CVE-2022-29464 | CRITICAL | 9.8 | 100.0% | Apr 18, 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file... |
| CVE-2022-24841 | HIGH | 8.1 | 0.8% | Apr 18, 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu... |
| CVE-2022-29458 | HIGH | 7.1 | 1.3% | Apr 18, 2022 | ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_... |
| CVE-2022-29457 | HIGH | 8.8 | 7.7% | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 ... |
| CVE-2022-24863 | HIGH | 7.5 | 2.3% | Apr 18, 2022 | http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now