2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26211 | CRITICAL | 9.8 | 2.8% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-26210 | CRITICAL | 9.8 | 5.7% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-26209 | CRITICAL | 9.8 | 2.2% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-26208 | CRITICAL | 9.8 | 2.8% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-26207 | CRITICAL | 9.8 | 2.2% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-26206 | CRITICAL | 9.8 | 2.2% | Mar 15, 2022 | Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137... |
| CVE-2022-23989 | HIGH | 7.5 | 0.9% | Mar 15, 2022 | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x b... |
| CVE-2022-25498 | CRITICAL | 9.8 | 2.9% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /... |
| CVE-2022-25497 | MEDIUM | 5.3 | 3.6% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. |
| CVE-2022-25495 | CRITICAL | 9.8 | 2.0% | Mar 15, 2022 | The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and e... |
| CVE-2022-25494 | CRITICAL | 9.8 | 1.1% | Mar 15, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php. |
| CVE-2022-25493 | MEDIUM | 6.1 | 0.8% | Mar 15, 2022 | HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php. |
| CVE-2022-25492 | CRITICAL | 9.8 | 1.6% | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. |
| CVE-2022-25491 | HIGH | 7.5 | 1.5% | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. |
| CVE-2022-25490 | CRITICAL | 9.8 | 1.6% | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. |
| CVE-2022-25489 | MEDIUM | 5.4 | 1.5% | Mar 15, 2022 | Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /w... |
| CVE-2022-25488 | CRITICAL | 9.8 | 7.1% | Mar 15, 2022 | Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. |
| CVE-2022-25487 | CRITICAL | 9.8 | 54.8% | Mar 15, 2022 | Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. |
| CVE-2022-25486 | HIGH | 7.8 | 10.0% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. |
| CVE-2022-25485 | HIGH | 7.8 | 7.9% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. |
| CVE-2022-27218 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenk... |
| CVE-2022-27217 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Je... |
| CVE-2022-27216 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file ... |
| CVE-2022-27215 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permiss... |
| CVE-2022-27214 | MEDIUM | 4.3 | 0.5% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now