2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30809 | CRITICAL | 9.8 | 1.1% | Jun 2, 2022 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. |
| CVE-2022-30808 | CRITICAL | 9.8 | 16.1% | Jun 2, 2022 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. |
| CVE-2022-30797 | CRITICAL | 9.8 | 1.1% | Jun 2, 2022 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. |
| CVE-2022-30521 | CRITICAL | 9.8 | 13.6% | Jun 2, 2022 | The LAN-side Web-Configuration Interface has Stack-based Buffer Overflow vulnerability in the D-Link Wi-Fi router firmwa... |
| CVE-2022-30512 | CRITICAL | 9.8 | 9.6% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. |
| CVE-2022-30511 | CRITICAL | 9.8 | 3.5% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. |
| CVE-2022-30510 | CRITICAL | 9.8 | 3.7% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. |
| CVE-2022-30506 | CRITICAL | 9.8 | 2.5% | Jun 2, 2022 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code thro... |
| CVE-2022-30490 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/u... |
| CVE-2022-30481 | CRITICAL | 9.8 | 1.5% | Jun 2, 2022 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid param... |
| CVE-2022-30478 | CRITICAL | 9.8 | 1.5% | Jun 2, 2022 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the key... |
| CVE-2022-30470 | CRITICAL | 9.8 | 2.5% | Jun 2, 2022 | In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file result... |
| CVE-2022-30423 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile uploa... |
| CVE-2022-30352 | CRITICAL | 9.8 | 1.8% | Jun 2, 2022 | phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" p... |
| CVE-2022-30324 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privi... |
| CVE-2022-29777 | CRITICAL | 9.8 | 6.9% | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via t... |
| CVE-2022-29776 | CRITICAL | 9.8 | 6.9% | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via ... |
| CVE-2022-29730 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest p... |
| CVE-2022-29712 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and ... |
| CVE-2022-29659 | CRITICAL | 9.8 | 1.9% | Jun 2, 2022 | Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. |
| CVE-2022-28945 | CRITICAL | 9.8 | 2.0% | Jun 2, 2022 | An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file. |
| CVE-2022-28605 | CRITICAL | 9.8 | 1.8% | Jun 2, 2022 | Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in li... |
| CVE-2022-25237 | CRITICAL | 9.8 | 56.2% | Jun 2, 2022 | Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude patt... |
| CVE-2022-24702 | CRITICAL | 9.8 | 5.6% | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to ac... |
| CVE-2022-24240 | CRITICAL | 9.8 | 1.1% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in shows... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now