2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-27466CRITICAL9.8MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
CVE-2022-28571CRITICAL9.8D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.
CVE-2022-1300CRITICAL9.8Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of thi...
CVE-2022-25301CRITICAL9.8All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attribute...
CVE-2022-25842CRITICAL9.8All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Ex...
CVE-2022-25767CRITICAL9.8All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a ma...
CVE-2022-24437CRITICAL9.8The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack featu...
CVE-2022-23923CRITICAL9.8All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main...
CVE-2022-22143CRITICAL9.8The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validatio...
CVE-2022-21189CRITICAL9.8The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the...
CVE-2022-21167CRITICAL9.8All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function ...
CVE-2022-28481CRITICAL9.8CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
CVE-2022-28994CRITICAL9.8Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
CVE-2022-28480CRITICAL9.8ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
CVE-2022-28452CRITICAL9.8Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-1531CRITICAL9.8SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint...
CVE-2022-29906CRITICAL9.8The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf...
CVE-2022-29904CRITICAL9.8The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQ...
CVE-2022-24449CRITICAL9.8Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML doc...
CVE-2022-29556CRITICAL9.8The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub...
CVE-2022-29081CRITICAL9.8Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnera...
CVE-2022-29411CRITICAL9.8SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQL...
CVE-2022-28114CRITICAL9.1DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
CVE-2022-28101CRITICAL9Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML...
CVE-2022-28719CRITICAL9.8Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker w...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now