2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-29502CRITICAL9.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
CVE-2022-28606CRITICAL9.8An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can ...
CVE-2022-28533CRITICAL9.8Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
CVE-2022-28530CRITICAL9.8Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
CVE-2022-28120CRITICAL9.8Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0...
CVE-2022-27588CRITICAL9.8We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later
CVE-2022-26415CRITICAL9.1On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13...
CVE-2022-1388CRITICAL9.8On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13...
CVE-2022-28461CRITICAL9.8mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
CVE-2022-1575CRITICAL9.6Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remot...
CVE-2022-28890CRITICAL9.8A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This i...
CVE-2022-30292CRITICAL10Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
CVE-2022-30284CRITICAL9.8In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client applicat...
CVE-2022-29155CRITICAL9.8In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql ...
CVE-2022-20777CRITICAL9.9Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from ...
CVE-2022-28557CRITICAL9.8There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20...
CVE-2022-29347CRITICAL9.8An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP...
CVE-2022-28568CRITICAL9.8Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrat...
CVE-2022-28512CRITICAL9.8A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantas...
CVE-2022-28082CRITICAL9.8Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlLis...
CVE-2022-28111CRITICAL9.8MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulner...
CVE-2022-28055CRITICAL9.8Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
CVE-2022-27431CRITICAL9.8Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/memb...
CVE-2022-27420CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact paramete...
CVE-2022-27413CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now