2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25003 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame... |
| CVE-2022-24232 | HIGH | 7.8 | 1.4% | Feb 24, 2022 | A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via ... |
| CVE-2022-23922 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file... |
| CVE-2022-23135 | MEDIUM | 6.5 | 1.4% | Feb 24, 2022 | There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of us... |
| CVE-2022-23104 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file... |
| CVE-2022-21824 | HIGH | 8.2 | 21.5% | Feb 24, 2022 | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passe... |
| CVE-2022-0710 | MEDIUM | 6.1 | 2.4% | Feb 24, 2022 | The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via ... |
| CVE-2022-0683 | MEDIUM | 6.1 | 3.2% | Feb 24, 2022 | The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escap... |
| CVE-2022-0653 | MEDIUM | 6.1 | 2.7% | Feb 24, 2022 | The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due ... |
| CVE-2022-0651 | HIGH | 7.5 | 33.0% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
| CVE-2022-0546 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing a... |
| CVE-2022-0545 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds... |
| CVE-2022-0544 | MEDIUM | 5.5 | 1.1% | Feb 24, 2022 | An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read ... |
| CVE-2022-22794 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userli... |
| CVE-2022-22793 | HIGH | 7.5 | 0.7% | Feb 24, 2022 | Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer... |
| CVE-2022-22349 | MEDIUM | 4.3 | 1.0% | Feb 24, 2022 | IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not p... |
| CVE-2022-24708 | MEDIUM | 5.4 | 0.5% | Feb 24, 2022 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Track... |
| CVE-2022-24707 | HIGH | 8.8 | 7.2% | Feb 24, 2022 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-b... |
| CVE-2022-24687 | MEDIUM | 6.5 | 1.4% | Feb 24, 2022 | HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gatew... |
| CVE-2022-0732 | HIGH | 7.5 | 2.5% | Feb 24, 2022 | The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth... |
| CVE-2022-25838 | HIGH | 8.1 | 0.9% | Feb 24, 2022 | Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "... |
| CVE-2022-25809 | CRITICAL | 9.8 | 3.1% | Feb 24, 2022 | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice comma... |
| CVE-2022-25643 | CRITICAL | 9.8 | 2.1% | Feb 24, 2022 | seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The... |
| CVE-2022-25640 | HIGH | 7.5 | 1.3% | Feb 24, 2022 | In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can ... |
| CVE-2022-25638 | MEDIUM | 6.5 | 0.6% | Feb 24, 2022 | In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now