2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-23900CRITICAL9.8A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an att...
CVE-2022-27818CRITICAL9.1SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.
CVE-2022-26613CRITICAL9.8PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
CVE-2022-24786CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not pars...
CVE-2022-1253CRITICAL9.8Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established...
CVE-2022-23441CRITICAL9.1A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow ...
CVE-2022-28468CRITICAL9.8Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-28467CRITICAL9.8Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter...
CVE-2022-28116CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-28115CRITICAL9.8Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-27304CRITICAL9.8Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CVE-2022-27124CRITICAL9.8Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-27123CRITICAL9.8Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-26628CRITICAL9.8Matrimony v1.0 was discovered to contain a SQL injection vulnerability via the Password parameter.
CVE-2022-28219CRITICAL9.8Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote...
CVE-2022-26635CRITICAL9.8PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. N...
CVE-2022-1212CRITICAL9.8Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execu...
CVE-2022-24231CRITICAL9.8Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
CVE-2022-26585CRITICAL9.8Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CVE-2022-0790CRITICAL9.6Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engag...
CVE-2022-0466CRITICAL9.6Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convi...
CVE-2022-0452CRITICAL9.6Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform ...
CVE-2022-1162CRITICAL9.8A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE...
CVE-2022-25569CRITICAL9.8Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthentic...
CVE-2022-0990CRITICAL9.1Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now