2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34125MEDIUM6.5front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive informati...
CVE-2022-30076MEDIUM5.3ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames...
CVE-2022-28353MEDIUM6.1In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.
CVE-2022-43128Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2022-42245. Reason: This record is a duplicate of CVE-2022-...
CVE-2022-40946HIGH7.5On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t...
CVE-2022-38841HIGH8.8Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn...
CVE-2022-38840HIGH7.5cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file uplo...
CVE-2022-37306MEDIUM6.1OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
CVE-2022-37255HIGH7.5TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646...
CVE-2022-37186MEDIUM5.9In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time...
CVE-2022-37705MEDIUM6.7A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerab...
CVE-2022-37704MEDIUM6.7Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/ru...
CVE-2022-2525CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
CVE-2022-47522HIGH7.5The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) t...
CVE-2022-45030HIGH8.8A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may...
CVE-2022-43699MEDIUM4.3OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be a...
CVE-2022-43698MEDIUM4.3OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
CVE-2022-43697MEDIUM6.1OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
CVE-2022-43696MEDIUM6.1OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
CVE-2022-48178MEDIUM5.4X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via ...
CVE-2022-48177MEDIUM5.4X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v...
CVE-2022-46886MEDIUM6.1There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redi...
CVE-2022-47501HIGH7.5Arbitrary file reading vulnerability in Apache Software Foundation Apache OFBiz when using the Solr plugin. This is a  p...
CVE-2022-4893Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3748CRITICAL9.8Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now