2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25138 | MEDIUM | 5.4 | 0.6% | Mar 3, 2022 | Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name paramete... |
| CVE-2022-0841 | CRITICAL | 9.8 | 2.7% | Mar 3, 2022 | OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4. |
| CVE-2022-0753 | MEDIUM | 6.1 | 0.8% | Mar 3, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. |
| CVE-2022-25031 | HIGH | 7.8 | 0.2% | Mar 3, 2022 | Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate pr... |
| CVE-2022-22706 | HIGH | 7.8 | 1.2% | Mar 3, 2022 | Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects ... |
| CVE-2022-23648 | HIGH | 7.5 | 27.4% | Mar 3, 2022 | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to ve... |
| CVE-2022-0528 | HIGH | 7.5 | 1.0% | Mar 3, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. |
| CVE-2022-23849 | MEDIUM | 6.6 | 0.2% | Mar 3, 2022 | The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application becaus... |
| CVE-2022-24573 | MEDIUM | 6.1 | 0.6% | Mar 3, 2022 | A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unaut... |
| CVE-2022-24563 | MEDIUM | 5.4 | 0.9% | Mar 3, 2022 | In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=opt... |
| CVE-2022-25471 | HIGH | 8.1 | 0.8% | Mar 3, 2022 | An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access an... |
| CVE-2022-25146 | MEDIUM | 5.3 | 0.6% | Mar 3, 2022 | The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 doe... |
| CVE-2022-25089 | CRITICAL | 9.8 | 18.6% | Mar 3, 2022 | Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL... |
| CVE-2022-22909 | HIGH | 8.8 | 45.4% | Mar 3, 2022 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack... |
| CVE-2022-26171 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. |
| CVE-2022-26170 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. |
| CVE-2022-26169 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. |
| CVE-2022-25399 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. |
| CVE-2022-25398 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. |
| CVE-2022-25396 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search pa... |
| CVE-2022-25395 | CRITICAL | 9.6 | 1.0% | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) a... |
| CVE-2022-25394 | CRITICAL | 9.8 | 1.5% | Mar 2, 2022 | Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under... |
| CVE-2022-25393 | HIGH | 7.5 | 1.2% | Mar 2, 2022 | Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-25115 | HIGH | 7.8 | 1.5% | Mar 2, 2022 | A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners C... |
| CVE-2022-25114 | MEDIUM | 6.1 | 0.7% | Mar 2, 2022 | Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now