2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46122 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=. |
| CVE-2022-46121 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=. |
| CVE-2022-46120 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=. |
| CVE-2022-46119 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=. |
| CVE-2022-46118 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=. |
| CVE-2022-46117 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=. |
| CVE-2022-46074 | HIGH | 8.8 | 0.5% | Dec 14, 2022 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin a... |
| CVE-2022-23517 | HIGH | 7.5 | 1.5% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails... |
| CVE-2022-44898 | HIGH | 7.8 | 0.4% | Dec 14, 2022 | The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x8010... |
| CVE-2022-23516 | HIGH | 7.5 | 1.1% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2022-23514 | HIGH | 7.5 | 1.7% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2022-23512 | HIGH | 8.1 | 0.8% | Dec 14, 2022 | MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Inject... |
| CVE-2022-34271 | HIGH | 8.8 | 1.4% | Dec 14, 2022 | A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This i... |
| CVE-2022-23503 | HIGH | 8.8 | 0.8% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and... |
| CVE-2022-23500 | HIGH | 7.5 | 0.7% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1... |
| CVE-2022-4440 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea... |
| CVE-2022-4439 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the u... |
| CVE-2022-4438 | HIGH | 8.8 | 0.7% | Dec 14, 2022 | Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user... |
| CVE-2022-4437 | HIGH | 8.8 | 0.7% | Dec 14, 2022 | Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea... |
| CVE-2022-4436 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit ... |
| CVE-2022-42140 | HIGH | 7.2 | 2.4% | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose. |
| CVE-2022-42139 | HIGH | 8.8 | 18.2% | Dec 14, 2022 | Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL. |
| CVE-2022-40264 | HIGH | 7.1 | 0.3% | Dec 14, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Elect... |
| CVE-2022-37155 | HIGH | 8.8 | 40.0% | Dec 14, 2022 | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. |
| CVE-2022-2660 | HIGH | 7.5 | 0.6% | Dec 13, 2022 | Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic k... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now