2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38276HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
CVE-2022-38275HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
CVE-2022-38274HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
CVE-2022-38273HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
CVE-2022-38272HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
CVE-2022-29061HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2022-40299HIGH7.8In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the pr...
CVE-2022-40297HIGH7.8UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode i...
CVE-2022-40281HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has...
CVE-2022-40280HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio...
CVE-2022-36084HIGH8.8cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl startin...
CVE-2022-38269HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38268HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38267HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38265HIGH7.2Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete...
CVE-2022-36100HIGH8.8XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Start...
CVE-2022-36099HIGH8.8XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting ...
CVE-2022-3167HIGH8.8Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
CVE-2022-38258HIGH8.1A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) o...
CVE-2022-36093HIGH7.1XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the dis...
CVE-2022-36092HIGH7.5XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10....
CVE-2022-38260HIGH7.2Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de...
CVE-2022-38255HIGH7.2Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interv...
CVE-2022-37857HIGH7.5bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but sto...
CVE-2022-36091HIGH7.5XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now