2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29859 | CRITICAL | 9.8 | 1.2% | Apr 27, 2022 | component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structur... |
| CVE-2022-27336 | CRITICAL | 9.8 | 20.0% | Apr 27, 2022 | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php. |
| CVE-2022-28464 | CRITICAL | 9 | 1.2% | Apr 27, 2022 | Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution. |
| CVE-2022-27332 | CRITICAL | 9.1 | 1.0% | Apr 27, 2022 | An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.... |
| CVE-2022-28524 | CRITICAL | 9.8 | 0.9% | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. |
| CVE-2022-28521 | CRITICAL | 9.8 | 1.5% | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. |
| CVE-2022-24883 | CRITICAL | 9.8 | 2.2% | Apr 26, 2022 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authenticatio... |
| CVE-2022-24881 | CRITICAL | 9.8 | 2.9% | Apr 26, 2022 | Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, a... |
| CVE-2022-27985 | CRITICAL | 9.8 | 6.9% | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. |
| CVE-2022-27984 | CRITICAL | 9.8 | 6.9% | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/te... |
| CVE-2022-27469 | CRITICAL | 9.8 | 1.3% | Apr 26, 2022 | Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF). |
| CVE-2022-27468 | CRITICAL | 9.8 | 1.9% | Apr 26, 2022 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code vi... |
| CVE-2022-27299 | CRITICAL | 9.8 | 1.6% | Apr 26, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php. |
| CVE-2022-24706 | CRITICAL | 9.8 | 92.3% | Apr 26, 2022 | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticati... |
| CVE-2022-29806 | CRITICAL | 9.8 | 66.3% | Apr 26, 2022 | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an... |
| CVE-2022-29499 | CRITICAL | 9.8 | 55.4% | Apr 26, 2022 | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorr... |
| CVE-2022-23457 | CRITICAL | 9.8 | 2.7% | Apr 25, 2022 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver... |
| CVE-2022-25866 | CRITICAL | 9.8 | 3.8% | Apr 25, 2022 | The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling ... |
| CVE-2022-1391 | CRITICAL | 9.8 | 13.6% | Apr 25, 2022 | The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in requ... |
| CVE-2022-1390 | CRITICAL | 9.8 | 22.1% | Apr 25, 2022 | The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which... |
| CVE-2022-0782 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in... |
| CVE-2022-0769 | CRITICAL | 9.8 | 8.4% | Apr 25, 2022 | The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it... |
| CVE-2022-0693 | CRITICAL | 9.8 | 7.2% | Apr 25, 2022 | The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_... |
| CVE-2022-0657 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat... |
| CVE-2022-0541 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now