2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1166MEDIUM5.3The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not in...
CVE-2022-1165CRITICAL9.1The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi...
CVE-2022-1164MEDIUM6.1The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature
CVE-2022-0958MEDIUM4.8The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to...
CVE-2022-0901MEDIUM6.1The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputtin...
CVE-2022-0887HIGH7.2The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget be...
CVE-2022-0884MEDIUM4.8The Profile Builder WordPress plugin before 3.6.8 does not sanitise and escape Form Fields titles and description, which...
CVE-2022-0864MEDIUM6.1The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.22.9 does not sanitise and escape the updraft_interval...
CVE-2022-0837MEDIUM5.4The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia SMS service, allowing ...
CVE-2022-0830MEDIUM6.5The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting for...
CVE-2022-0825MEDIUM5.4The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any cu...
CVE-2022-0709HIGH7.5The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's bookin...
CVE-2022-0537HIGH7.2The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and...
CVE-2022-0431MEDIUM6.1The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before ...
CVE-2022-0404MEDIUM6.5The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me...
CVE-2022-0403HIGH8.1The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn...
CVE-2022-1026HIGH8.6Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information...
CVE-2022-28063MEDIUM4.9Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
CVE-2022-28062HIGH8.8Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers ...
CVE-2022-27436MEDIUM4.8A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attack...
CVE-2022-27435HIGH8.8An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to uploa...
CVE-2022-26616MEDIUM6.1PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks...
CVE-2022-24191MEDIUM5.5In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memo...
CVE-2022-1225MEDIUM6.5Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
CVE-2022-1224MEDIUM6.5Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now