2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0643MEDIUM6.1The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it b...
CVE-2022-0641MEDIUM6.1The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting...
CVE-2022-0621MEDIUM6.1The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an ad...
CVE-2022-0620MEDIUM6.1The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it ...
CVE-2022-0619MEDIUM6.1The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it bac...
CVE-2022-0600MEDIUM6.1The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting ...
CVE-2022-0599MEDIUM6.1The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id par...
CVE-2022-0595MEDIUM5.4The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th...
CVE-2022-0499HIGH8.8The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and ...
CVE-2022-0493MEDIUM4.9The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi...
CVE-2022-0479CRITICAL9.8The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter be...
CVE-2022-0450MEDIUM5.4The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving me...
CVE-2022-0397MEDIUM5.4The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter befo...
CVE-2022-0388MEDIUM4.8The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, a...
CVE-2022-23884CRITICAL9.8Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by Purc...
CVE-2022-0342CRITICAL9.8An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70...
CVE-2022-23882CRITICAL9.8TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
CVE-2022-25757CRITICAL9.8In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as...
CVE-2022-27950MEDIUM5.5In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error conditio...
CVE-2022-26273CRITICAL9.8EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnera...
CVE-2022-24303CRITICAL9.1Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
CVE-2022-26271HIGH7.574cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controlle...
CVE-2022-26268CRITICAL9.8Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books...
CVE-2022-26259HIGH7.8A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X...
CVE-2022-26258CRITICAL9.8D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now