2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1161CRITICAL9.8An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, a...
CVE-2022-1157LOW2.4Missing sanitization of logged exception messages in all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior ...
CVE-2022-1067MEDIUM6.5Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without...
CVE-2022-0999HIGH8.8An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO ...
CVE-2022-0835MEDIUM5.5AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-pri...
CVE-2022-0552MEDIUM5.9A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logg...
CVE-2022-29035LOW2.7In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom impleme...
CVE-2022-27156MEDIUM5.4Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
CVE-2022-27115CRITICAL9.8In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for fi...
CVE-2022-27111MEDIUM5.4Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend a...
CVE-2022-1023HIGH7.2The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, ...
CVE-2022-1008HIGH7.2The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege use...
CVE-2022-1007MEDIUM6.1The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outpu...
CVE-2022-1006HIGH7.2The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing C...
CVE-2022-0989HIGH7.5An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load...
CVE-2022-0969MEDIUM4.8The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload ...
CVE-2022-0949CRITICAL9.8The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does no...
CVE-2022-0920HIGH7.5The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end...
CVE-2022-0919MEDIUM5.3The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching boo...
CVE-2022-0914MEDIUM6.5The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attac...
CVE-2022-0892MEDIUM6.1The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back ...
CVE-2022-0840MEDIUM4.8The Easy Social Icons WordPress plugin before 3.2.1 does not properly escape the image_file field when adding a new soci...
CVE-2022-0828HIGH7.5The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a downlo...
CVE-2022-0728MEDIUM4.8The Easy Smooth Scroll Links WordPress plugin before 2.23.1 does not sanitise and escape its settings, which could allow...
CVE-2022-0531MEDIUM6.1The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now