2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38304HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai...
CVE-2022-38303HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /emp...
CVE-2022-38302HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai...
CVE-2022-38298HIGH8.8Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via re...
CVE-2022-35572HIGH7.5On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to c...
CVE-2022-38610HIGH7.2Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed...
CVE-2022-38606HIGH7.2Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed...
CVE-2022-38605HIGH7.2Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi...
CVE-2022-36174HIGH8.1FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulne...
CVE-2022-36173HIGH8.1FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the Fre...
CVE-2022-2979HIGH7.8Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially re...
CVE-2022-29490HIGH8.8Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an...
CVE-2022-36102HIGH7.2Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a cert...
CVE-2022-31226HIGH7.8Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could poten...
CVE-2022-3178HIGH7.8Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-37797HIGH7.5In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket ha...
CVE-2022-37734HIGH7.5graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes...
CVE-2022-37835HIGH7.5Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and inf...
CVE-2022-36259HIGH7.5A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to ex...
CVE-2022-36258HIGH7.5A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-36257HIGH7.5A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi...
CVE-2022-36256HIGH7.5A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit...
CVE-2022-36255HIGH7.5A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-34109HIGH7.1An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to t...
CVE-2022-34108HIGH7.1An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now