2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24859 | MEDIUM | 5.5 | 1.3% | Apr 18, 2022 | PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF f... |
| CVE-2022-1112 | MEDIUM | 5.4 | 0.3% | Apr 18, 2022 | The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not ... |
| CVE-2022-1091 | MEDIUM | 6.1 | 1.2% | Apr 18, 2022 | The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the... |
| CVE-2022-1090 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high... |
| CVE-2022-1088 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which ... |
| CVE-2022-1063 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti... |
| CVE-2022-1054 | MEDIUM | 5.3 | 3.6% | Apr 18, 2022 | The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting... |
| CVE-2022-1037 | HIGH | 7.2 | 1.3% | Apr 18, 2022 | The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead... |
| CVE-2022-1020 | CRITICAL | 9.8 | 26.2% | Apr 18, 2022 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c... |
| CVE-2022-1001 | MEDIUM | 4.8 | 4.2% | Apr 18, 2022 | The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set... |
| CVE-2022-0994 | MEDIUM | 4.8 | 2.8% | Apr 18, 2022 | The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi... |
| CVE-2022-0879 | MEDIUM | 6.1 | 1.2% | Apr 18, 2022 | The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it b... |
| CVE-2022-0785 | CRITICAL | 9.8 | 9.2% | Apr 18, 2022 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i... |
| CVE-2022-0780 | MEDIUM | 6.1 | 0.8% | Apr 18, 2022 | The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti... |
| CVE-2022-0765 | MEDIUM | 5.4 | 4.0% | Apr 18, 2022 | The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source tran... |
| CVE-2022-0737 | MEDIUM | 4.8 | 0.8% | Apr 18, 2022 | The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil... |
| CVE-2022-0707 | MEDIUM | 4.3 | 0.5% | Apr 18, 2022 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes... |
| CVE-2022-0706 | MEDIUM | 4.8 | 0.6% | Apr 18, 2022 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the... |
| CVE-2022-0661 | HIGH | 7.2 | 40.6% | Apr 18, 2022 | The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the ... |
| CVE-2022-27853 | MEDIUM | 4.8 | 0.5% | Apr 18, 2022 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0.... |
| CVE-2022-27652 | MEDIUM | 5.3 | 0.2% | Apr 18, 2022 | A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability... |
| CVE-2022-27530 | HIGH | 7.8 | 0.8% | Apr 18, 2022 | A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the alloca... |
| CVE-2022-27529 | HIGH | 7.8 | 0.7% | Apr 18, 2022 | A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond ... |
| CVE-2022-27526 | HIGH | 7.8 | 1.4% | Apr 18, 2022 | A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerab... |
| CVE-2022-27525 | HIGH | 7.8 | 1.6% | Apr 18, 2022 | A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now