2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-46122HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=.
CVE-2022-46121HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=.
CVE-2022-46120HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=.
CVE-2022-46119HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=.
CVE-2022-46118HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=.
CVE-2022-46117HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.
CVE-2022-46074HIGH8.8Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin a...
CVE-2022-23517HIGH7.5rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails...
CVE-2022-44898HIGH7.8The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x8010...
CVE-2022-23516HIGH7.5Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri...
CVE-2022-23514HIGH7.5Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri...
CVE-2022-23512HIGH8.1MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Inject...
CVE-2022-34271HIGH8.8A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This i...
CVE-2022-23503HIGH8.8TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and...
CVE-2022-23500HIGH7.5TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1...
CVE-2022-4440HIGH8.8Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea...
CVE-2022-4439HIGH8.8Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the u...
CVE-2022-4438HIGH8.8Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user...
CVE-2022-4437HIGH8.8Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea...
CVE-2022-4436HIGH8.8Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit ...
CVE-2022-42140HIGH7.2Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
CVE-2022-42139HIGH8.8Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.
CVE-2022-40264HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Elect...
CVE-2022-37155HIGH8.8RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
CVE-2022-2660HIGH7.5Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now