2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0643 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Bank Mellat WordPress plugin through 1.3.7 does not sanitize and escape the orderId parameter before outputting it b... |
| CVE-2022-0641 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting... |
| CVE-2022-0621 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The dTabs WordPress plugin through 1.4 does not sanitize and escape the tab parameter before outputting it back in an ad... |
| CVE-2022-0620 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it ... |
| CVE-2022-0619 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Database Peek WordPress plugin through 1.2 does not sanitize and escape the match parameter before outputting it bac... |
| CVE-2022-0600 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting ... |
| CVE-2022-0599 | MEDIUM | 6.1 | 1.7% | Mar 28, 2022 | The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id par... |
| CVE-2022-0595 | MEDIUM | 5.4 | 13.6% | Mar 28, 2022 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th... |
| CVE-2022-0499 | HIGH | 8.8 | 0.6% | Mar 28, 2022 | The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and ... |
| CVE-2022-0493 | MEDIUM | 4.9 | 1.4% | Mar 28, 2022 | The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi... |
| CVE-2022-0479 | CRITICAL | 9.8 | 44.1% | Mar 28, 2022 | The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter be... |
| CVE-2022-0450 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving me... |
| CVE-2022-0397 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter befo... |
| CVE-2022-0388 | MEDIUM | 4.8 | 0.6% | Mar 28, 2022 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, a... |
| CVE-2022-23884 | CRITICAL | 9.8 | 2.5% | Mar 28, 2022 | Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by Purc... |
| CVE-2022-0342 | CRITICAL | 9.8 | 84.8% | Mar 28, 2022 | An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70... |
| CVE-2022-23882 | CRITICAL | 9.8 | 1.1% | Mar 28, 2022 | TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php. |
| CVE-2022-25757 | CRITICAL | 9.8 | 2.4% | Mar 28, 2022 | In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as... |
| CVE-2022-27950 | MEDIUM | 5.5 | 0.4% | Mar 28, 2022 | In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error conditio... |
| CVE-2022-26273 | CRITICAL | 9.8 | 1.1% | Mar 28, 2022 | EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnera... |
| CVE-2022-24303 | CRITICAL | 9.1 | 2.7% | Mar 28, 2022 | Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. |
| CVE-2022-26271 | HIGH | 7.5 | 4.6% | Mar 28, 2022 | 74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controlle... |
| CVE-2022-26268 | CRITICAL | 9.8 | 0.9% | Mar 28, 2022 | Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books... |
| CVE-2022-26259 | HIGH | 7.8 | 2.4% | Mar 28, 2022 | A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X... |
| CVE-2022-26258 | CRITICAL | 9.8 | 81.1% | Mar 28, 2022 | D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now