2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23900 | CRITICAL | 9.8 | 3.6% | Apr 7, 2022 | A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an att... |
| CVE-2022-27818 | CRITICAL | 9.1 | 1.7% | Apr 7, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service. |
| CVE-2022-26613 | CRITICAL | 9.8 | 1.4% | Apr 6, 2022 | PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php. |
| CVE-2022-24786 | CRITICAL | 9.8 | 1.9% | Apr 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not pars... |
| CVE-2022-1253 | CRITICAL | 9.8 | 2.0% | Apr 6, 2022 | Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established... |
| CVE-2022-23441 | CRITICAL | 9.1 | 0.9% | Apr 6, 2022 | A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow ... |
| CVE-2022-28468 | CRITICAL | 9.8 | 1.6% | Apr 5, 2022 | Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-28467 | CRITICAL | 9.8 | 1.1% | Apr 5, 2022 | Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter... |
| CVE-2022-28116 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. |
| CVE-2022-28115 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. |
| CVE-2022-27304 | CRITICAL | 9.8 | 1.3% | Apr 5, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. |
| CVE-2022-27124 | CRITICAL | 9.8 | 1.1% | Apr 5, 2022 | Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-27123 | CRITICAL | 9.8 | 1.3% | Apr 5, 2022 | Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. |
| CVE-2022-26628 | CRITICAL | 9.8 | 1.4% | Apr 5, 2022 | Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter. |
| CVE-2022-28219 | CRITICAL | 9.8 | 97.0% | Apr 5, 2022 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote... |
| CVE-2022-26635 | CRITICAL | 9.8 | 21.4% | Apr 5, 2022 | PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. N... |
| CVE-2022-1212 | CRITICAL | 9.8 | 1.7% | Apr 5, 2022 | Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execu... |
| CVE-2022-24231 | CRITICAL | 9.8 | 1.7% | Apr 5, 2022 | Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student. |
| CVE-2022-26585 | CRITICAL | 9.8 | 5.6% | Apr 5, 2022 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. |
| CVE-2022-0790 | CRITICAL | 9.6 | 0.9% | Apr 5, 2022 | Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engag... |
| CVE-2022-0466 | CRITICAL | 9.6 | 0.6% | Apr 5, 2022 | Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convi... |
| CVE-2022-0452 | CRITICAL | 9.6 | 0.7% | Apr 5, 2022 | Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform ... |
| CVE-2022-1162 | CRITICAL | 9.8 | 76.2% | Apr 4, 2022 | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE... |
| CVE-2022-25569 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthentic... |
| CVE-2022-0990 | CRITICAL | 9.1 | 1.3% | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now