2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-29859CRITICAL9.8component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structur...
CVE-2022-27336CRITICAL9.8Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CVE-2022-28464CRITICAL9Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.
CVE-2022-27332CRITICAL9.1An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication....
CVE-2022-28524CRITICAL9.8ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
CVE-2022-28521CRITICAL9.8ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.
CVE-2022-24883CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authenticatio...
CVE-2022-24881CRITICAL9.8Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, a...
CVE-2022-27985CRITICAL9.8CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CVE-2022-27984CRITICAL9.8CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/te...
CVE-2022-27469CRITICAL9.8Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).
CVE-2022-27468CRITICAL9.8Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code vi...
CVE-2022-27299CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
CVE-2022-24706CRITICAL9.8In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticati...
CVE-2022-29806CRITICAL9.8ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an...
CVE-2022-29499CRITICAL9.8The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorr...
CVE-2022-23457CRITICAL9.8ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver...
CVE-2022-25866CRITICAL9.8The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling ...
CVE-2022-1391CRITICAL9.8The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in requ...
CVE-2022-1390CRITICAL9.8The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which...
CVE-2022-0782CRITICAL9.8The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in...
CVE-2022-0769CRITICAL9.8The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it...
CVE-2022-0693CRITICAL9.8The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_...
CVE-2022-0657CRITICAL9.8The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validat...
CVE-2022-0541CRITICAL9.8The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now