2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-0767CRITICAL9.9Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
CVE-2022-0766CRITICAL9.8Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
CVE-2022-26496CRITICAL9.8In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the...
CVE-2022-26495CRITICAL9.8In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0...
CVE-2022-0845CRITICAL9.8Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
CVE-2022-25069CRITICAL9.6Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers ...
CVE-2022-25312CRITICAL9.1An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is kn...
CVE-2022-26318CRITICAL9.8On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner...
CVE-2022-0839CRITICAL9.8Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
CVE-2022-26201CRITICAL9.8Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
CVE-2022-0848CRITICAL9.8OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.
CVE-2022-0730CRITICAL9.8Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
CVE-2022-22947CRITICAL10In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe...
CVE-2022-0265CRITICAL9.8Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
CVE-2022-24724CRITICAL9.8cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 a...
CVE-2022-25125CRITICAL9.8MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CVE-2022-23899CRITICAL9.8MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
CVE-2022-23898CRITICAL9.8MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao...
CVE-2022-0841CRITICAL9.8OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
CVE-2022-25089CRITICAL9.8Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL...
CVE-2022-26171CRITICAL9.8Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2022-26170CRITICAL9.8Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
CVE-2022-26169CRITICAL9.8Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
CVE-2022-25399CRITICAL9.8Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
CVE-2022-25398CRITICAL9.8Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now