2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28585 | CRITICAL | 9.8 | 0.9% | May 3, 2022 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php |
| CVE-2022-27962 | CRITICAL | 9.8 | 1.0% | May 3, 2022 | Bluecms 1.6 has a SQL injection vulnerability at cooike. |
| CVE-2022-28561 | CRITICAL | 9.8 | 9.3% | May 3, 2022 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03... |
| CVE-2022-28560 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 1... |
| CVE-2022-28118 | CRITICAL | 9.8 | 2.8% | May 3, 2022 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. |
| CVE-2022-1378 | CRITICAL | 9.8 | 19.6% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p... |
| CVE-2022-1377 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_r... |
| CVE-2022-1376 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_p... |
| CVE-2022-1375 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_s... |
| CVE-2022-1374 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_u... |
| CVE-2022-1372 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog... |
| CVE-2022-1371 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe... |
| CVE-2022-1370 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRE... |
| CVE-2022-1369 | CRITICAL | 9.8 | 1.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRe... |
| CVE-2022-1367 | CRITICAL | 9.8 | 21.1% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle... |
| CVE-2022-1366 | CRITICAL | 9.8 | 19.6% | May 2, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle... |
| CVE-2022-1281 | CRITICAL | 9.8 | 23.5% | May 2, 2022 | The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is a... |
| CVE-2022-0783 | CRITICAL | 9.8 | 6.7% | May 2, 2022 | The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous par... |
| CVE-2022-0773 | CRITICAL | 9.8 | 42.2% | May 2, 2022 | The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in... |
| CVE-2022-0771 | CRITICAL | 9.8 | 1.6% | May 2, 2022 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before usi... |
| CVE-2022-28573 | CRITICAL | 9.8 | 27.5% | May 2, 2022 | D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting... |
| CVE-2022-28056 | CRITICAL | 9.8 | 1.3% | May 2, 2022 | ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/... |
| CVE-2022-28054 | CRITICAL | 9.8 | 28.2% | May 2, 2022 | Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execut... |
| CVE-2022-27982 | CRITICAL | 9.8 | 2.0% | May 2, 2022 | RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the ... |
| CVE-2022-27466 | CRITICAL | 9.8 | 1.6% | May 2, 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now