2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26174CRITICAL9.8A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a ...
CVE-2022-26148CRITICAL9.8An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the a...
CVE-2022-23352HIGH7.5An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
CVE-2022-23350MEDIUM5.4BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23349HIGH8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-23348MEDIUM5.3BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CVE-2022-23347HIGH7.5BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
CVE-2022-23346HIGH8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
CVE-2022-23345HIGH7.5BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
CVE-2022-24775HIGH7.5guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header par...
CVE-2022-24766CRITICAL9.8mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or ser...
CVE-2022-0760CRITICAL9.8The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using ...
CVE-2022-0747CRITICAL9.8The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it i...
CVE-2022-0739CRITICAL9.8The BookingPress WordPress plugin before 1.0.11 fails to properly sanitize user supplied POST data before it is used in ...
CVE-2022-0694CRITICAL9.8The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before u...
CVE-2022-0687HIGH8.8The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user...
CVE-2022-0681MEDIUM6.5The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which ...
CVE-2022-0640MEDIUM6.1The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputt...
CVE-2022-0628MEDIUM6.1The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it bac...
CVE-2022-0627MEDIUM6.1The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in a...
CVE-2022-0616MEDIUM4.3The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow a...
CVE-2022-0591CRITICAL9.1The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, lead...
CVE-2022-0590MEDIUM4.8The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allo...
CVE-2022-0515MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
CVE-2022-0514MEDIUM6.5Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now