2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0269HIGH8Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
CVE-2022-23858HIGH8.8A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges ...
CVE-2022-23857MEDIUM6.5model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Sma...
CVE-2022-23856MEDIUM5.3An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changin...
CVE-2022-23855CRITICAL9.8An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenanc...
CVE-2022-23852CRITICAL9.8Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_...
CVE-2022-23850HIGH7.8xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a cr...
CVE-2022-23808MEDIUM6.1An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup ...
CVE-2022-23807MEDIUM4.3An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated t...
CVE-2022-23366CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
CVE-2022-23365CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.
CVE-2022-23364CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.
CVE-2022-23363CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.
CVE-2022-21708MEDIUM6.5graphql-go is a GraphQL server with a focus on ease of use. In versions prior to 1.3.0 there exists a DoS vulnerability ...
CVE-2022-21707HIGH8.1wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and ...
CVE-2022-23837HIGH7.5In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the grap...
CVE-2022-22553CRITICAL9.8Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability ...
CVE-2022-22552MEDIUM6.1Dell EMC AppSync versions 3.9 to 4.3 contain a clickjacking vulnerability in AppSync. A remote unauthenticated attacker ...
CVE-2022-22551HIGH8.8DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a...
CVE-2022-23728MEDIUM6.1Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.
CVE-2022-23130MEDIUM5.5Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A to 4.04E, Mitsubishi Electric GENESIS64 ...
CVE-2022-23129MEDIUM5.5Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior ...
CVE-2022-23128CRITICAL9.8Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4....
CVE-2022-23127MEDIUM6.1Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS...
CVE-2022-0323HIGH8.8Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now