2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25138MEDIUM5.4Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name paramete...
CVE-2022-0841CRITICAL9.8OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
CVE-2022-0753MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
CVE-2022-25031HIGH7.8Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate pr...
CVE-2022-22706HIGH7.8Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects ...
CVE-2022-23648HIGH7.5containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to ve...
CVE-2022-0528HIGH7.5Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.
CVE-2022-23849MEDIUM6.6The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application becaus...
CVE-2022-24573MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unaut...
CVE-2022-24563MEDIUM5.4In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=opt...
CVE-2022-25471HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access an...
CVE-2022-25146MEDIUM5.3The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 doe...
CVE-2022-25089CRITICAL9.8Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL...
CVE-2022-22909HIGH8.8HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack...
CVE-2022-26171CRITICAL9.8Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-26170CRITICAL9.8Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
CVE-2022-26169CRITICAL9.8Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
CVE-2022-25399CRITICAL9.8Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-25398CRITICAL9.8Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CVE-2022-25396CRITICAL9.8Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search pa...
CVE-2022-25395CRITICAL9.6Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) a...
CVE-2022-25394CRITICAL9.8Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under...
CVE-2022-25393HIGH7.5Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-25115HIGH7.8A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners C...
CVE-2022-25114MEDIUM6.1Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now