2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0767 | CRITICAL | 9.9 | 1.0% | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. |
| CVE-2022-0766 | CRITICAL | 9.8 | 1.3% | Mar 7, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. |
| CVE-2022-26496 | CRITICAL | 9.8 | 3.5% | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the... |
| CVE-2022-26495 | CRITICAL | 9.8 | 2.7% | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0... |
| CVE-2022-0845 | CRITICAL | 9.8 | 1.0% | Mar 5, 2022 | Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. |
| CVE-2022-25069 | CRITICAL | 9.6 | 1.8% | Mar 5, 2022 | Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers ... |
| CVE-2022-25312 | CRITICAL | 9.1 | 2.7% | Mar 5, 2022 | An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is kn... |
| CVE-2022-26318 | CRITICAL | 9.8 | 78.3% | Mar 4, 2022 | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner... |
| CVE-2022-0839 | CRITICAL | 9.8 | 2.9% | Mar 4, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. |
| CVE-2022-26201 | CRITICAL | 9.8 | 1.5% | Mar 4, 2022 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. |
| CVE-2022-0848 | CRITICAL | 9.8 | 35.4% | Mar 4, 2022 | OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11. |
| CVE-2022-0730 | CRITICAL | 9.8 | 3.5% | Mar 3, 2022 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. |
| CVE-2022-22947 | CRITICAL | 10 | 98.3% | Mar 3, 2022 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe... |
| CVE-2022-0265 | CRITICAL | 9.8 | 2.8% | Mar 3, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. |
| CVE-2022-24724 | CRITICAL | 9.8 | 4.2% | Mar 3, 2022 | cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 a... |
| CVE-2022-25125 | CRITICAL | 9.8 | 7.2% | Mar 3, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. |
| CVE-2022-23899 | CRITICAL | 9.8 | 1.1% | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. |
| CVE-2022-23898 | CRITICAL | 9.8 | 7.7% | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao... |
| CVE-2022-0841 | CRITICAL | 9.8 | 2.7% | Mar 3, 2022 | OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4. |
| CVE-2022-25089 | CRITICAL | 9.8 | 18.6% | Mar 3, 2022 | Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL... |
| CVE-2022-26171 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter. |
| CVE-2022-26170 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. |
| CVE-2022-26169 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. |
| CVE-2022-25399 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. |
| CVE-2022-25398 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now