2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26133 | CRITICAL | 9.8 | 71.4% | Apr 20, 2022 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and l... |
| CVE-2022-0540 | CRITICAL | 9.8 | 88.3% | Apr 20, 2022 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially... |
| CVE-2022-1039 | CRITICAL | 9.8 | 1.1% | Apr 20, 2022 | The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the ... |
| CVE-2022-0567 | CRITICAL | 9.1 | 1.0% | Apr 20, 2022 | A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n... |
| CVE-2022-24860 | CRITICAL | 9.8 | 1.6% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-code... |
| CVE-2022-27862 | CRITICAL | 9.8 | 1.6% | Apr 19, 2022 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al... |
| CVE-2022-21445 | CRITICAL | 9.8 | 62.0% | Apr 19, 2022 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ... |
| CVE-2022-21431 | CRITICAL | 10 | 2.0% | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21420 | CRITICAL | 9.8 | 1.4% | Apr 19, 2022 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are... |
| CVE-2022-0993 | CRITICAL | 9.8 | 7.5% | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to... |
| CVE-2022-0992 | CRITICAL | 9.8 | 2.9% | Apr 19, 2022 | The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to... |
| CVE-2022-27104 | CRITICAL | 9.8 | 1.2% | Apr 19, 2022 | An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3. |
| CVE-2022-25648 | CRITICAL | 9.8 | 4.6% | Apr 19, 2022 | The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(rem... |
| CVE-2022-27927 | CRITICAL | 9.8 | 13.6% | Apr 19, 2022 | A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application d... |
| CVE-2022-29464 | CRITICAL | 9.8 | 100.0% | Apr 18, 2022 | Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file... |
| CVE-2022-1020 | CRITICAL | 9.8 | 26.2% | Apr 18, 2022 | The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c... |
| CVE-2022-0785 | CRITICAL | 9.8 | 9.2% | Apr 18, 2022 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i... |
| CVE-2022-25226 | CRITICAL | 10 | 10.9% | Apr 18, 2022 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?... |
| CVE-2022-26631 | CRITICAL | 9.8 | 1.1% | Apr 18, 2022 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter... |
| CVE-2022-27423 | CRITICAL | 9.8 | 0.9% | Apr 15, 2022 | Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php... |
| CVE-2022-26809 | CRITICAL | 9.8 | 91.8% | Apr 15, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability |
| CVE-2022-24497 | CRITICAL | 9.8 | 34.9% | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2022-24491 | CRITICAL | 9.8 | 33.8% | Apr 15, 2022 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2022-27158 | CRITICAL | 9.8 | 1.2% | Apr 15, 2022 | pearweb < 1.32 suffers from Deserialization of Untrusted Data. |
| CVE-2022-27157 | CRITICAL | 9.8 | 1.1% | Apr 15, 2022 | pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now