2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0362 | CRITICAL | 9.8 | 1.4% | Jan 26, 2022 | SQL Injection in Packagist showdoc/showdoc prior to 2.10.3. |
| CVE-2022-23959 | CRITICAL | 9.1 | 2.0% | Jan 26, 2022 | In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cac... |
| CVE-2022-0332 | CRITICAL | 9.8 | 44.9% | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv... |
| CVE-2022-23944 | CRITICAL | 9.1 | 79.0% | Jan 25, 2022 | User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |
| CVE-2022-23126 | CRITICAL | 9.8 | 2.3% | Jan 24, 2022 | TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, ... |
| CVE-2022-23855 | CRITICAL | 9.8 | 1.7% | Jan 24, 2022 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenanc... |
| CVE-2022-23852 | CRITICAL | 9.8 | 4.7% | Jan 24, 2022 | Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_... |
| CVE-2022-23366 | CRITICAL | 9.8 | 6.7% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php. |
| CVE-2022-23365 | CRITICAL | 9.8 | 1.2% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php. |
| CVE-2022-23364 | CRITICAL | 9.8 | 1.3% | Jan 21, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php. |
| CVE-2022-23363 | CRITICAL | 9.8 | 1.0% | Jan 21, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. |
| CVE-2022-22553 | CRITICAL | 9.8 | 1.1% | Jan 21, 2022 | Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability ... |
| CVE-2022-23128 | CRITICAL | 9.8 | 2.9% | Jan 21, 2022 | Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.... |
| CVE-2022-0318 | CRITICAL | 9.8 | 2.1% | Jan 21, 2022 | Heap-based Buffer Overflow in vim/vim prior to 8.2. |
| CVE-2022-23315 | CRITICAL | 9.8 | 1.8% | Jan 21, 2022 | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileCon... |
| CVE-2022-23314 | CRITICAL | 9.8 | 1.6% | Jan 21, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do. |
| CVE-2022-22930 | CRITICAL | 9.8 | 23.7% | Jan 21, 2022 | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execu... |
| CVE-2022-22929 | CRITICAL | 9.8 | 2.6% | Jan 21, 2022 | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attac... |
| CVE-2022-22928 | CRITICAL | 9.8 | 2.5% | Jan 21, 2022 | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary co... |
| CVE-2022-21679 | CRITICAL | 9.8 | 1.1% | Jan 19, 2022 | Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization pol... |
| CVE-2022-22769 | CRITICAL | 9 | 0.9% | Jan 19, 2022 | The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons,... |
| CVE-2022-23221 | CRITICAL | 9.8 | 64.8% | Jan 19, 2022 | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG... |
| CVE-2022-21391 | CRITICAL | 9.9 | 1.2% | Jan 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21390 | CRITICAL | 10 | 2.4% | Jan 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21389 | CRITICAL | 10 | 1.9% | Jan 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now