2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48946MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: udf: Fix preallocation discarding at indirect exten...
CVE-2022-4974MEDIUM6.3The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request For...
CVE-2022-4973MEDIUM5.4WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploite...
CVE-2022-4972HIGH7.5The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev...
CVE-2022-4971MEDIUM6.1The Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'urls' parameter cal...
CVE-2022-4534MEDIUM5.3The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, ...
CVE-2022-4541MEDIUM6.1The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value...
CVE-2022-49041MEDIUM4.4Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functiona...
CVE-2022-49040MEDIUM4.4Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functional...
CVE-2022-49039MEDIUM6.7Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 al...
CVE-2022-49038HIGH7.8Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client...
CVE-2022-49037MEDIUM6.5Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client befo...
CVE-2022-43845HIGH7.5IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the fail...
CVE-2022-2439HIGH7.2The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserializ...
CVE-2022-48945MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: vivid: fix compose size exceed boundary syz...
CVE-2022-4533MEDIUM5.3The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including...
CVE-2022-25770HIGH7.5Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, whic...
CVE-2022-25768MEDIUM6.5The logic in place to facilitate the update process via the user interface lacks access control to verify if permission ...
CVE-2022-25777MEDIUM6.5Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses ...
CVE-2022-25776MEDIUM6.5Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be ...
CVE-2022-25775HIGH7.2Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports ...
CVE-2022-25774MEDIUM5.4Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications ...
CVE-2022-25769CRITICAL9.1ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be...
CVE-2022-39068MEDIUM6.5There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an a...
CVE-2022-3459MEDIUM5.3The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and in...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now