2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38304 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai... |
| CVE-2022-38303 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /emp... |
| CVE-2022-38302 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai... |
| CVE-2022-38298 | HIGH | 8.8 | 0.6% | Sep 12, 2022 | Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via re... |
| CVE-2022-35572 | HIGH | 7.5 | 0.7% | Sep 12, 2022 | On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to c... |
| CVE-2022-38610 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed... |
| CVE-2022-38606 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed... |
| CVE-2022-38605 | HIGH | 7.2 | 0.8% | Sep 12, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi... |
| CVE-2022-36174 | HIGH | 8.1 | 0.4% | Sep 12, 2022 | FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulne... |
| CVE-2022-36173 | HIGH | 8.1 | 0.8% | Sep 12, 2022 | FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the Fre... |
| CVE-2022-2979 | HIGH | 7.8 | 0.2% | Sep 12, 2022 | Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially re... |
| CVE-2022-29490 | HIGH | 8.8 | 0.5% | Sep 12, 2022 | Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an... |
| CVE-2022-36102 | HIGH | 7.2 | 0.6% | Sep 12, 2022 | Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a cert... |
| CVE-2022-31226 | HIGH | 7.8 | 0.2% | Sep 12, 2022 | Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could poten... |
| CVE-2022-3178 | HIGH | 7.8 | 0.4% | Sep 12, 2022 | Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-37797 | HIGH | 7.5 | 2.0% | Sep 12, 2022 | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket ha... |
| CVE-2022-37734 | HIGH | 7.5 | 2.1% | Sep 12, 2022 | graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes... |
| CVE-2022-37835 | HIGH | 7.5 | 0.6% | Sep 12, 2022 | Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and inf... |
| CVE-2022-36259 | HIGH | 7.5 | 0.9% | Sep 12, 2022 | A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to ex... |
| CVE-2022-36258 | HIGH | 7.5 | 0.8% | Sep 12, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ... |
| CVE-2022-36257 | HIGH | 7.5 | 0.8% | Sep 12, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi... |
| CVE-2022-36256 | HIGH | 7.5 | 0.8% | Sep 12, 2022 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit... |
| CVE-2022-36255 | HIGH | 7.5 | 0.8% | Sep 12, 2022 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ... |
| CVE-2022-34109 | HIGH | 7.1 | 0.3% | Sep 12, 2022 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to t... |
| CVE-2022-34108 | HIGH | 7.1 | 0.3% | Sep 12, 2022 | An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now