2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29078 | CRITICAL | 9.8 | 32.4% | Apr 25, 2022 | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[... |
| CVE-2022-28093 | CRITICAL | 9.8 | 2.8% | Apr 25, 2022 | SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which al... |
| CVE-2022-27429 | CRITICAL | 9.8 | 1.1% | Apr 25, 2022 | Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/upda... |
| CVE-2022-27311 | CRITICAL | 9.8 | 1.5% | Apr 25, 2022 | Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL. |
| CVE-2022-29264 | CRITICAL | 9.8 | 1.7% | Apr 25, 2022 | An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur. |
| CVE-2022-29077 | CRITICAL | 9.8 | 2.1% | Apr 25, 2022 | A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or exec... |
| CVE-2022-27342 | CRITICAL | 9.8 | 1.0% | Apr 22, 2022 | Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult(). |
| CVE-2022-27341 | CRITICAL | 9.8 | 1.2% | Apr 22, 2022 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. |
| CVE-2022-1440 | CRITICAL | 9.8 | 3.8% | Apr 22, 2022 | Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If bot... |
| CVE-2022-27404 | CRITICAL | 9.8 | 2.6% | Apr 22, 2022 | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the functi... |
| CVE-2022-26674 | CRITICAL | 9.8 | 2.5% | Apr 22, 2022 | ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary m... |
| CVE-2022-26672 | CRITICAL | 9.8 | 1.1% | Apr 22, 2022 | ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token ... |
| CVE-2022-28443 | CRITICAL | 9.1 | 0.9% | Apr 21, 2022 | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. |
| CVE-2022-28439 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid... |
| CVE-2022-28438 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=... |
| CVE-2022-28437 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=... |
| CVE-2022-28436 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=... |
| CVE-2022-28435 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displayg... |
| CVE-2022-28434 | CRITICAL | 9.8 | 0.9% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&... |
| CVE-2022-28433 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=... |
| CVE-2022-28432 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=displ... |
| CVE-2022-28431 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&social=remove&s... |
| CVE-2022-28429 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=delete&msgid=. |
| CVE-2022-28427 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/inbox.php&action=read&msgid=. |
| CVE-2022-28426 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/pagerole.php&action=edit&roleid... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now