2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2504CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Softw...
CVE-2022-48341HIGH8.8ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis...
CVE-2022-48149CRITICAL9.8Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via ...
CVE-2022-45600HIGH8.8Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers...
CVE-2022-45599CRITICAL9.8Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al...
CVE-2022-39983CRITICAL9.8File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attack...
CVE-2022-29273MEDIUM6.1pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
CVE-2022-43873HIGH8.8An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute c...
CVE-2022-43870MEDIUM6.5IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files...
CVE-2022-43578MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-...
CVE-2022-41567MEDIUM5.4The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerabi...
CVE-2022-41566MEDIUM5.4The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows...
CVE-2022-41565MEDIUM5.4The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO ...
CVE-2022-41217CRITICAL9.8Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malici...
CVE-2022-41216MEDIUM6.5Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste...
CVE-2022-2883HIGH7.5In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv...
CVE-2022-38779MEDIUM6.1An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th...
CVE-2022-46637CRITICAL9.8Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
CVE-2022-48282HIGH7.2Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitra...
CVE-2022-45677CRITICAL9.8SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student...
CVE-2022-45564CRITICAL9.8SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute...
CVE-2022-3353HIGH7.5 A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attac...
CVE-2022-31394HIGH7.5Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party ...
CVE-2022-4897MEDIUM6.1The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back i...
CVE-2022-4791MEDIUM5.4The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape o...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now