2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0781 | CRITICAL | 9.8 | 12.4% | May 23, 2022 | The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL state... |
| CVE-2022-1813 | CRITICAL | 9.8 | 2.7% | May 22, 2022 | OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. |
| CVE-2022-31267 | CRITICAL | 9.8 | 17.7% | May 21, 2022 | Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile da... |
| CVE-2022-31259 | CRITICAL | 9.8 | 21.6% | May 21, 2022 | The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /... |
| CVE-2022-1775 | CRITICAL | 9.8 | 2.1% | May 20, 2022 | Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2. |
| CVE-2022-29186 | CRITICAL | 9.8 | 1.1% | May 20, 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and ... |
| CVE-2022-28618 | CRITICAL | 9.8 | 1.8% | May 20, 2022 | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Sto... |
| CVE-2022-22972 | CRITICAL | 9.8 | 52.8% | May 20, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff... |
| CVE-2022-28995 | CRITICAL | 9.8 | 2.2% | May 20, 2022 | Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function... |
| CVE-2022-28531 | CRITICAL | 9.8 | 14.2% | May 20, 2022 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtuse... |
| CVE-2022-29165 | CRITICAL | 10 | 1.9% | May 20, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered i... |
| CVE-2022-28660 | CRITICAL | 9.8 | 1.1% | May 20, 2022 | The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X... |
| CVE-2022-30887 | CRITICAL | 9.8 | 24.8% | May 20, 2022 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component ... |
| CVE-2022-30886 | CRITICAL | 9.8 | 2.0% | May 20, 2022 | School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter ... |
| CVE-2022-30518 | CRITICAL | 9.8 | 1.7% | May 20, 2022 | ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id par... |
| CVE-2022-29873 | CRITICAL | 9.8 | 1.7% | May 20, 2022 | A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate paramete... |
| CVE-2022-29023 | CRITICAL | 9.8 | 2.1% | May 20, 2022 | A buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to ca... |
| CVE-2022-29022 | CRITICAL | 9.8 | 2.0% | May 20, 2022 | A buffer overflow vulnerability exists in the razeraccessory driver of OpenRazer up to version v3.3.0 allows attackers t... |
| CVE-2022-29021 | CRITICAL | 9.8 | 2.0% | May 20, 2022 | A buffer overflow vulnerability exists in the razerkbd driver of OpenRazer up to version v3.3.0 allows attackers to caus... |
| CVE-2022-28993 | CRITICAL | 9.8 | 1.6% | May 20, 2022 | Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request. |
| CVE-2022-28106 | CRITICAL | 9.8 | 1.1% | May 20, 2022 | Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POS... |
| CVE-2022-28105 | CRITICAL | 9.8 | 1.0% | May 20, 2022 | Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id param... |
| CVE-2022-28104 | CRITICAL | 9.8 | 1.8% | May 20, 2022 | Foxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-26633 | CRITICAL | 9.8 | 1.6% | May 20, 2022 | Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Acti... |
| CVE-2022-26632 | CRITICAL | 9.8 | 1.6% | May 20, 2022 | Multi-Vendor Online Groceries Management System v1.0 was discovered to contain a blind SQL injection vulnerability via t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now