2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0269 | HIGH | 8 | 0.5% | Jan 24, 2022 | Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. |
| CVE-2022-23858 | HIGH | 8.8 | 1.1% | Jan 24, 2022 | A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges ... |
| CVE-2022-23857 | MEDIUM | 6.5 | 0.9% | Jan 24, 2022 | model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Sma... |
| CVE-2022-23856 | MEDIUM | 5.3 | 1.0% | Jan 24, 2022 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changin... |
| CVE-2022-23855 | CRITICAL | 9.8 | 1.7% | Jan 24, 2022 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenanc... |
| CVE-2022-23852 | CRITICAL | 9.8 | 4.7% | Jan 24, 2022 | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_... |
| CVE-2022-23850 | HIGH | 7.8 | 0.9% | Jan 23, 2022 | xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a cr... |
| CVE-2022-23808 | MEDIUM | 6.1 | 8.0% | Jan 22, 2022 | An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup ... |
| CVE-2022-23807 | MEDIUM | 4.3 | 0.7% | Jan 22, 2022 | An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated t... |
| CVE-2022-23366 | CRITICAL | 9.8 | 6.7% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. |
| CVE-2022-23365 | CRITICAL | 9.8 | 1.2% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php. |
| CVE-2022-23364 | CRITICAL | 9.8 | 1.3% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php. |
| CVE-2022-23363 | CRITICAL | 9.8 | 1.0% | Jan 21, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. |
| CVE-2022-21708 | MEDIUM | 6.5 | 1.2% | Jan 21, 2022 | graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability ... |
| CVE-2022-21707 | HIGH | 8.1 | 0.9% | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and ... |
| CVE-2022-23837 | HIGH | 7.5 | 5.3% | Jan 21, 2022 | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the grap... |
| CVE-2022-22553 | CRITICAL | 9.8 | 1.1% | Jan 21, 2022 | Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability ... |
| CVE-2022-22552 | MEDIUM | 6.1 | 0.7% | Jan 21, 2022 | Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker ... |
| CVE-2022-22551 | HIGH | 8.8 | 0.4% | Jan 21, 2022 | DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a... |
| CVE-2022-23728 | MEDIUM | 6.1 | 0.1% | Jan 21, 2022 | Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011. |
| CVE-2022-23130 | MEDIUM | 5.5 | 1.0% | Jan 21, 2022 | Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 ... |
| CVE-2022-23129 | MEDIUM | 5.5 | 0.2% | Jan 21, 2022 | Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior ... |
| CVE-2022-23128 | CRITICAL | 9.8 | 2.9% | Jan 21, 2022 | Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.... |
| CVE-2022-23127 | MEDIUM | 6.1 | 1.6% | Jan 21, 2022 | Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS... |
| CVE-2022-0323 | HIGH | 8.8 | 0.7% | Jan 21, 2022 | Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now