2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-26133CRITICAL9.8SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and l...
CVE-2022-0540CRITICAL9.8A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially...
CVE-2022-1039CRITICAL9.8The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the ...
CVE-2022-0567CRITICAL9.1A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n...
CVE-2022-24860CRITICAL9.8Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-code...
CVE-2022-27862CRITICAL9.8Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al...
CVE-2022-21445CRITICAL9.8Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ...
CVE-2022-21431CRITICAL10Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21420CRITICAL9.8Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are...
CVE-2022-0993CRITICAL9.8The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to...
CVE-2022-0992CRITICAL9.8The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows unauthenticated users to...
CVE-2022-27104CRITICAL9.8An Unauthenticated time-based blind SQL injection vulnerability exists in Forma LMS prior to v.1.4.3.
CVE-2022-25648CRITICAL9.8The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(rem...
CVE-2022-27927CRITICAL9.8A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application d...
CVE-2022-29464CRITICAL9.8Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file...
CVE-2022-1020CRITICAL9.8The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF c...
CVE-2022-0785CRITICAL9.8The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using i...
CVE-2022-25226CRITICAL10ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?...
CVE-2022-26631CRITICAL9.8Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter...
CVE-2022-27423CRITICAL9.8Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php...
CVE-2022-26809CRITICAL9.8Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2022-24497CRITICAL9.8Windows Network File System Remote Code Execution Vulnerability
CVE-2022-24491CRITICAL9.8Windows Network File System Remote Code Execution Vulnerability
CVE-2022-27158CRITICAL9.8pearweb < 1.32 suffers from Deserialization of Untrusted Data.
CVE-2022-27157CRITICAL9.8pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now