2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1166 | MEDIUM | 5.3 | 1.5% | Apr 4, 2022 | The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not in... |
| CVE-2022-1165 | CRITICAL | 9.1 | 1.6% | Apr 4, 2022 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi... |
| CVE-2022-1164 | MEDIUM | 6.1 | 0.8% | Apr 4, 2022 | The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature |
| CVE-2022-0958 | MEDIUM | 4.8 | 0.6% | Apr 4, 2022 | The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to... |
| CVE-2022-0901 | MEDIUM | 6.1 | 3.6% | Apr 4, 2022 | The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputtin... |
| CVE-2022-0887 | HIGH | 7.2 | 1.3% | Apr 4, 2022 | The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget be... |
| CVE-2022-0884 | MEDIUM | 4.8 | 0.6% | Apr 4, 2022 | The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which... |
| CVE-2022-0864 | MEDIUM | 6.1 | 6.4% | Apr 4, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval... |
| CVE-2022-0837 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing ... |
| CVE-2022-0830 | MEDIUM | 6.5 | 0.5% | Apr 4, 2022 | The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting for... |
| CVE-2022-0825 | MEDIUM | 5.4 | 0.8% | Apr 4, 2022 | The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu... |
| CVE-2022-0709 | HIGH | 7.5 | 1.6% | Apr 4, 2022 | The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's bookin... |
| CVE-2022-0537 | HIGH | 7.2 | 1.5% | Apr 4, 2022 | The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and... |
| CVE-2022-0431 | MEDIUM | 6.1 | 0.9% | Apr 4, 2022 | The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before ... |
| CVE-2022-0404 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me... |
| CVE-2022-0403 | HIGH | 8.1 | 1.2% | Apr 4, 2022 | The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn... |
| CVE-2022-1026 | HIGH | 8.6 | 15.1% | Apr 4, 2022 | Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information... |
| CVE-2022-28063 | MEDIUM | 4.9 | 1.1% | Apr 4, 2022 | Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products. |
| CVE-2022-28062 | HIGH | 8.8 | 1.7% | Apr 4, 2022 | Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers ... |
| CVE-2022-27436 | MEDIUM | 4.8 | 1.0% | Apr 4, 2022 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attack... |
| CVE-2022-27435 | HIGH | 8.8 | 1.7% | Apr 4, 2022 | An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to uploa... |
| CVE-2022-26616 | MEDIUM | 6.1 | 1.0% | Apr 4, 2022 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks... |
| CVE-2022-24191 | MEDIUM | 5.5 | 0.7% | Apr 4, 2022 | In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memo... |
| CVE-2022-1225 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6. |
| CVE-2022-1224 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now