2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0423MEDIUM5.4The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, a...
CVE-2022-0364MEDIUM5.4The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p...
CVE-2022-0229HIGH8.1The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe...
CVE-2022-25766HIGH8.8The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs w...
CVE-2022-24237HIGH8.8The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulner...
CVE-2022-24236LOW3.5An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed ...
CVE-2022-24235HIGH8.8A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges...
CVE-2022-26960CRITICAL9.1connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote...
CVE-2022-22394HIGH8.8The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by impr...
CVE-2022-26494MEDIUM4.8An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a ...
CVE-2022-25570MEDIUM6.5In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional pass...
CVE-2022-1035MEDIUM5.5Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-24656MEDIUM6.1HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opene...
CVE-2022-0415HIGH8.8Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CVE-2022-1004MEDIUM4.3Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###Acc...
CVE-2022-0475MEDIUM5.4Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code cou...
CVE-2022-25505CRITICAL9.8Taocms v3.0.2 was discovered to contain a SQL injection vulnerability via the id parameter in \include\Model\Category.ph...
CVE-2022-25481HIGH7.5ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce...
CVE-2022-25462HIGH7.5Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attack...
CVE-2022-26555MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execut...
CVE-2022-26247MEDIUM5.9TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability...
CVE-2022-26246MEDIUM6.1TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mai...
CVE-2022-25464MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers...
CVE-2022-24125HIGH8.8The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send ar...
CVE-2022-24126CRITICAL9.8A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 all...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now