2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1161 | CRITICAL | 9.8 | 4.9% | Apr 11, 2022 | An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, a... |
| CVE-2022-1157 | LOW | 2.4 | 0.6% | Apr 11, 2022 | Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior ... |
| CVE-2022-1067 | MEDIUM | 6.5 | 0.8% | Apr 11, 2022 | Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without... |
| CVE-2022-0999 | HIGH | 8.8 | 1.3% | Apr 11, 2022 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO ... |
| CVE-2022-0835 | MEDIUM | 5.5 | 0.2% | Apr 11, 2022 | AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-pri... |
| CVE-2022-0552 | MEDIUM | 5.9 | 1.1% | Apr 11, 2022 | A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logg... |
| CVE-2022-29035 | LOW | 2.7 | 0.6% | Apr 11, 2022 | In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom impleme... |
| CVE-2022-27156 | MEDIUM | 5.4 | 0.5% | Apr 11, 2022 | Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection. |
| CVE-2022-27115 | CRITICAL | 9.8 | 28.9% | Apr 11, 2022 | In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for fi... |
| CVE-2022-27111 | MEDIUM | 5.4 | 0.5% | Apr 11, 2022 | Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend a... |
| CVE-2022-1023 | HIGH | 7.2 | 1.5% | Apr 11, 2022 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, ... |
| CVE-2022-1008 | HIGH | 7.2 | 1.7% | Apr 11, 2022 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege use... |
| CVE-2022-1007 | MEDIUM | 6.1 | 1.6% | Apr 11, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outpu... |
| CVE-2022-1006 | HIGH | 7.2 | 1.5% | Apr 11, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing C... |
| CVE-2022-0989 | HIGH | 7.5 | 1.2% | Apr 11, 2022 | An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load... |
| CVE-2022-0969 | MEDIUM | 4.8 | 0.7% | Apr 11, 2022 | The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload ... |
| CVE-2022-0949 | CRITICAL | 9.8 | 8.0% | Apr 11, 2022 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does no... |
| CVE-2022-0920 | HIGH | 7.5 | 1.4% | Apr 11, 2022 | The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end... |
| CVE-2022-0919 | MEDIUM | 5.3 | 1.1% | Apr 11, 2022 | The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching boo... |
| CVE-2022-0914 | MEDIUM | 6.5 | 0.6% | Apr 11, 2022 | The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attac... |
| CVE-2022-0892 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back ... |
| CVE-2022-0840 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci... |
| CVE-2022-0828 | HIGH | 7.5 | 1.5% | Apr 11, 2022 | The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a downlo... |
| CVE-2022-0728 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow... |
| CVE-2022-0531 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now