2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24859MEDIUM5.5PyPDF2 is an open source python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF f...
CVE-2022-1112MEDIUM5.4The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not ...
CVE-2022-1091MEDIUM6.1The sanitisation step of the Safe SVG WordPress plugin before 1.9.10 can be bypassed by spoofing the content-type in the...
CVE-2022-1090MEDIUM4.8The Good & Bad Comments WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high...
CVE-2022-1088MEDIUM4.8The Page Security & Membership WordPress plugin through 1.5.15 does not sanitise and escape some of its settings, which ...
CVE-2022-1063MEDIUM4.8The Thank Me Later WordPress plugin through 3.3.4 does not sanitise and escape the Message Subject field before outputti...
CVE-2022-1054MEDIUM5.3The RSVP and Event Management Plugin WordPress plugin before 2.7.8 does not have any authorisation checks when exporting...
CVE-2022-1037HIGH7.2The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead...
CVE-2022-1020CRITICAL9.8The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c...
CVE-2022-1001MEDIUM4.8The WP Downgrade WordPress plugin before 1.2.3 only perform client side validation of its "WordPress Target Version" set...
CVE-2022-0994MEDIUM4.8The Hummingbird WordPress plugin before 3.3.2 does not sanitise and escape the Config Name, which could allow high privi...
CVE-2022-0879MEDIUM6.1The Caldera Forms WordPress plugin before 1.9.7 does not validate and escape the cf-api parameter before outputting it b...
CVE-2022-0785CRITICAL9.8The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i...
CVE-2022-0780MEDIUM6.1The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti...
CVE-2022-0765MEDIUM5.4The Loco Translate WordPress plugin before 2.6.1 does not properly remove inline events from elements in the source tran...
CVE-2022-0737MEDIUM4.8The Text Hover WordPress plugin before 4.2 does not sanitize and escape the text to hover, which could allow high privil...
CVE-2022-0707MEDIUM4.3The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes...
CVE-2022-0706MEDIUM4.8The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the...
CVE-2022-0661HIGH7.2The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the ...
CVE-2022-27853MEDIUM4.8Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) in Contest Gallery (WordPress plugin) <= 13.1.0....
CVE-2022-27652MEDIUM5.3A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability...
CVE-2022-27530HIGH7.8A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the alloca...
CVE-2022-27529HIGH7.8A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond ...
CVE-2022-27526HIGH7.8A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerab...
CVE-2022-27525HIGH7.8A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now