2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-24830CRITICAL9.8OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica...
CVE-2022-25865CRITICAL9.8The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling t...
CVE-2022-22282CRITICAL9.8SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource u...
CVE-2022-21190CRITICAL9.8This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-J...
CVE-2022-1715CRITICAL9.8Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.
CVE-2022-30413CRITICAL9.8Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_applic...
CVE-2022-30407CRITICAL9.8Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_...
CVE-2022-30395CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_cart.
CVE-2022-30392CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_sub_categor...
CVE-2022-30391CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_category.
CVE-2022-30387CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=pay_order.
CVE-2022-30386CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_featured.
CVE-2022-30385CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_order.
CVE-2022-30384CRITICAL9.8Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_inventory.
CVE-2022-29794CRITICAL9.8The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will ...
CVE-2022-25591CRITICAL9.1BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to del...
CVE-2022-22260CRITICAL9.1The kernel module has a UAF vulnerability.Successful exploitation of this vulnerability will affect data integrity and a...
CVE-2022-30370CRITICAL9.8Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
CVE-2022-29383CRITICAL9.8NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USE...
CVE-2022-23166CRITICAL9.8Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/...
CVE-2022-22796CRITICAL9.8Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, The...
CVE-2022-29363CRITICAL9.8Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. T...
CVE-2022-30001CRITICAL9.8Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editAgent.php?agent_id=.
CVE-2022-30000CRITICAL9.8Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editPayment.php?recipt_no=.
CVE-2022-29999CRITICAL9.8Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editClient.php?client_id=.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now