2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25396 | CRITICAL | 9.8 | 1.2% | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search pa... |
| CVE-2022-25395 | CRITICAL | 9.6 | 1.0% | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) a... |
| CVE-2022-25394 | CRITICAL | 9.8 | 1.5% | Mar 2, 2022 | Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under... |
| CVE-2022-25045 | CRITICAL | 9.8 | 1.3% | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to ... |
| CVE-2022-0675 | CRITICAL | 9.8 | 0.9% | Mar 2, 2022 | In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as th... |
| CVE-2022-23640 | CRITICAL | 9.8 | 1.4% | Mar 2, 2022 | Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-stre... |
| CVE-2022-23878 | CRITICAL | 9.8 | 2.1% | Mar 2, 2022 | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php. |
| CVE-2022-25016 | CRITICAL | 9.8 | 1.9% | Mar 2, 2022 | Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c... |
| CVE-2022-24306 | CRITICAL | 9.8 | 2.4% | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. |
| CVE-2022-24305 | CRITICAL | 9.8 | 2.7% | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege esc... |
| CVE-2022-25010 | CRITICAL | 9.1 | 1.0% | Mar 1, 2022 | The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system. |
| CVE-2022-24720 | CRITICAL | 9.8 | 2.6% | Mar 1, 2022 | image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, usi... |
| CVE-2022-25411 | CRITICAL | 9.8 | 2.8% | Feb 28, 2022 | A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary ... |
| CVE-2022-24711 | CRITICAL | 9.8 | 1.1% | Feb 28, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input... |
| CVE-2022-24571 | CRITICAL | 9.8 | 1.6% | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL... |
| CVE-2022-0768 | CRITICAL | 9.1 | 1.6% | Feb 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. |
| CVE-2022-0412 | CRITICAL | 9.8 | 74.6% | Feb 28, 2022 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d... |
| CVE-2022-25359 | CRITICAL | 9.1 | 37.3% | Feb 26, 2022 | On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele... |
| CVE-2022-25096 | CRITICAL | 9.8 | 2.1% | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-25095 | CRITICAL | 9.8 | 1.3% | Feb 26, 2022 | Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted... |
| CVE-2022-21706 | CRITICAL | 9.8 | 1.3% | Feb 26, 2022 | Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul... |
| CVE-2022-25263 | CRITICAL | 9.8 | 2.1% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration. |
| CVE-2022-25262 | CRITICAL | 9.8 | 1.4% | Feb 25, 2022 | In JetBrains Hub before 2022.1.14434, SAML request takeover was possible. |
| CVE-2022-25260 | CRITICAL | 9.1 | 2.4% | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF). |
| CVE-2022-25064 | CRITICAL | 9.8 | 39.8% | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the functio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now