2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24830 | CRITICAL | 9.8 | 2.9% | May 14, 2022 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica... |
| CVE-2022-25865 | CRITICAL | 9.8 | 6.9% | May 13, 2022 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling t... |
| CVE-2022-22282 | CRITICAL | 9.8 | 7.2% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource u... |
| CVE-2022-21190 | CRITICAL | 9.8 | 3.7% | May 13, 2022 | This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-J... |
| CVE-2022-1715 | CRITICAL | 9.8 | 1.3% | May 13, 2022 | Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07. |
| CVE-2022-30413 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_applic... |
| CVE-2022-30407 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_... |
| CVE-2022-30395 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart. |
| CVE-2022-30392 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_categor... |
| CVE-2022-30391 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category. |
| CVE-2022-30387 | CRITICAL | 9.8 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order. |
| CVE-2022-30386 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured. |
| CVE-2022-30385 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order. |
| CVE-2022-30384 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory. |
| CVE-2022-29794 | CRITICAL | 9.8 | 0.7% | May 13, 2022 | The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will ... |
| CVE-2022-25591 | CRITICAL | 9.1 | 2.7% | May 13, 2022 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to del... |
| CVE-2022-22260 | CRITICAL | 9.1 | 0.6% | May 13, 2022 | The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and a... |
| CVE-2022-30370 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type. |
| CVE-2022-29383 | CRITICAL | 9.8 | 49.0% | May 13, 2022 | NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USE... |
| CVE-2022-23166 | CRITICAL | 9.8 | 1.0% | May 12, 2022 | Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/... |
| CVE-2022-22796 | CRITICAL | 9.8 | 1.3% | May 12, 2022 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, The... |
| CVE-2022-29363 | CRITICAL | 9.8 | 1.2% | May 12, 2022 | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. T... |
| CVE-2022-30001 | CRITICAL | 9.8 | 1.1% | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=. |
| CVE-2022-30000 | CRITICAL | 9.8 | 1.1% | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=. |
| CVE-2022-29999 | CRITICAL | 9.8 | 1.1% | May 12, 2022 | Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now