2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27139 | CRITICAL | 9.8 | 3.8% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary ... |
| CVE-2022-28036 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php |
| CVE-2022-28035 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php |
| CVE-2022-28034 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php |
| CVE-2022-28033 | CRITICAL | 9.8 | 5.5% | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php |
| CVE-2022-28032 | CRITICAL | 9.8 | 6.0% | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php |
| CVE-2022-27473 | CRITICAL | 9.8 | 1.3% | Apr 12, 2022 | SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitr... |
| CVE-2022-27472 | CRITICAL | 9.8 | 1.3% | Apr 12, 2022 | SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitra... |
| CVE-2022-27165 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus |
| CVE-2022-27164 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers |
| CVE-2022-27163 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser |
| CVE-2022-27162 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser |
| CVE-2022-27161 | CRITICAL | 9.8 | 1.2% | Apr 12, 2022 | Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers |
| CVE-2022-0142 | CRITICAL | 9.8 | 2.6% | Apr 12, 2022 | The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or n... |
| CVE-2022-25752 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E... |
| CVE-2022-23450 | CRITICAL | 9.8 | 34.9% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag... |
| CVE-2022-29080 | CRITICAL | 9.8 | 2.3% | Apr 12, 2022 | The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call de... |
| CVE-2022-28347 | CRITICAL | 9.8 | 2.9% | Apr 12, 2022 | A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 befor... |
| CVE-2022-28346 | CRITICAL | 9.8 | 18.4% | Apr 12, 2022 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggre... |
| CVE-2022-24838 | CRITICAL | 9.8 | 31.6% | Apr 11, 2022 | Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails v... |
| CVE-2022-27577 | CRITICAL | 9.1 | 1.4% | Apr 11, 2022 | The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence n... |
| CVE-2022-27572 | CRITICAL | 9.8 | 1.3% | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 all... |
| CVE-2022-27571 | CRITICAL | 9.8 | 1.3% | Apr 11, 2022 | Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Rel... |
| CVE-2022-27570 | CRITICAL | 9.8 | 1.3% | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Releas... |
| CVE-2022-27569 | CRITICAL | 9.8 | 1.3% | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 all... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now