2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-45077HIGH8.8Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
CVE-2022-45069HIGH8.8Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
CVE-2022-45066HIGH8.8Auth. (subscriber+) Broken Access Control vulnerability in WooSwipe WooCommerce Gallery plugin <= 2.0.1 on WordPress.
CVE-2022-43506HIGH8.8SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an atta...
CVE-2022-43457HIGH8.8SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows a...
CVE-2022-43452HIGH8.8SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows ...
CVE-2022-43447HIGH8.8SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an...
CVE-2022-42533HIGH7.8In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This ...
CVE-2022-41791HIGH8.8Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
CVE-2022-41775HIGH8.8SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attack...
CVE-2022-40200HIGH8.8Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
CVE-2022-40192HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
CVE-2022-39179HIGH7.2 College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed...
CVE-2022-36924HIGH7.8The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr...
CVE-2022-36785HIGH7.5 D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file con...
CVE-2022-28768HIGH7.8The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local priv...
CVE-2022-28766HIGH7.3Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version ...
CVE-2022-23748HIGH7.8mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from whi...
CVE-2022-45071HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
CVE-2022-44725HIGH7.8OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. Th...
CVE-2022-43183HIGH8.8XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController...
CVE-2022-43179HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa...
CVE-2022-43163HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43162HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-44403HIGH7.2Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now