2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-25396CRITICAL9.8Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search pa...
CVE-2022-25395CRITICAL9.6Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) a...
CVE-2022-25394CRITICAL9.8Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under...
CVE-2022-25045CRITICAL9.8Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to ...
CVE-2022-0675CRITICAL9.8In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as th...
CVE-2022-23640CRITICAL9.8Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-stre...
CVE-2022-23878CRITICAL9.8seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVE-2022-25016CRITICAL9.8Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c...
CVE-2022-24306CRITICAL9.8Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
CVE-2022-24305CRITICAL9.8Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege esc...
CVE-2022-25010CRITICAL9.1The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
CVE-2022-24720CRITICAL9.8image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, usi...
CVE-2022-25411CRITICAL9.8A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary ...
CVE-2022-24711CRITICAL9.8CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input...
CVE-2022-24571CRITICAL9.8Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL...
CVE-2022-0768CRITICAL9.1Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
CVE-2022-0412CRITICAL9.8The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 d...
CVE-2022-25359CRITICAL9.1On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele...
CVE-2022-25096CRITICAL9.8Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-25095CRITICAL9.8Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted...
CVE-2022-21706CRITICAL9.8Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vul...
CVE-2022-25263CRITICAL9.8JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
CVE-2022-25262CRITICAL9.8In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.
CVE-2022-25260CRITICAL9.1JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).
CVE-2022-25064CRITICAL9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the functio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now