2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-29078CRITICAL9.8The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[...
CVE-2022-28093CRITICAL9.8SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which al...
CVE-2022-27429CRITICAL9.8Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/upda...
CVE-2022-27311CRITICAL9.8Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.
CVE-2022-29264CRITICAL9.8An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.
CVE-2022-29077CRITICAL9.8A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or exec...
CVE-2022-27342CRITICAL9.8Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
CVE-2022-27341CRITICAL9.8JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
CVE-2022-1440CRITICAL9.8Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If bot...
CVE-2022-27404CRITICAL9.8FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the functi...
CVE-2022-26674CRITICAL9.8ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary m...
CVE-2022-26672CRITICAL9.8ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token ...
CVE-2022-28443CRITICAL9.1UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
CVE-2022-28439CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid...
CVE-2022-28438CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=...
CVE-2022-28437CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=...
CVE-2022-28436CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=...
CVE-2022-28435CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displayg...
CVE-2022-28434CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&...
CVE-2022-28433CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=...
CVE-2022-28432CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=displ...
CVE-2022-28431CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&s...
CVE-2022-28429CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=.
CVE-2022-28427CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=.
CVE-2022-28426CRITICAL9.8Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now