2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29502 | CRITICAL | 9.8 | 1.6% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| CVE-2022-28606 | CRITICAL | 9.8 | 1.4% | May 5, 2022 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can ... |
| CVE-2022-28533 | CRITICAL | 9.8 | 1.5% | May 5, 2022 | Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. |
| CVE-2022-28530 | CRITICAL | 9.8 | 1.5% | May 5, 2022 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. |
| CVE-2022-28120 | CRITICAL | 9.8 | 1.0% | May 5, 2022 | Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0... |
| CVE-2022-27588 | CRITICAL | 9.8 | 1.2% | May 5, 2022 | We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later |
| CVE-2022-26415 | CRITICAL | 9.1 | 0.7% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-1388 | CRITICAL | 9.8 | 100.0% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-28461 | CRITICAL | 9.8 | 0.9% | May 5, 2022 | mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. |
| CVE-2022-1575 | CRITICAL | 9.6 | 2.2% | May 5, 2022 | Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remot... |
| CVE-2022-28890 | CRITICAL | 9.8 | 2.3% | May 5, 2022 | A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This i... |
| CVE-2022-30292 | CRITICAL | 10 | 3.5% | May 4, 2022 | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call. |
| CVE-2022-30284 | CRITICAL | 9.8 | 4.6% | May 4, 2022 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client applicat... |
| CVE-2022-29155 | CRITICAL | 9.8 | 69.9% | May 4, 2022 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql ... |
| CVE-2022-20777 | CRITICAL | 9.9 | 10.8% | May 4, 2022 | Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from ... |
| CVE-2022-28557 | CRITICAL | 9.8 | 21.6% | May 4, 2022 | There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20... |
| CVE-2022-29347 | CRITICAL | 9.8 | 2.1% | May 4, 2022 | An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP... |
| CVE-2022-28568 | CRITICAL | 9.8 | 4.1% | May 4, 2022 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrat... |
| CVE-2022-28512 | CRITICAL | 9.8 | 1.3% | May 4, 2022 | A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantas... |
| CVE-2022-28082 | CRITICAL | 9.8 | 8.2% | May 4, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlLis... |
| CVE-2022-28111 | CRITICAL | 9.8 | 1.6% | May 4, 2022 | MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulner... |
| CVE-2022-28055 | CRITICAL | 9.8 | 1.5% | May 4, 2022 | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. |
| CVE-2022-27431 | CRITICAL | 9.8 | 1.0% | May 4, 2022 | Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/memb... |
| CVE-2022-27420 | CRITICAL | 9.8 | 1.4% | May 4, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact paramete... |
| CVE-2022-27413 | CRITICAL | 9.8 | 2.9% | May 3, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now