2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-47131MEDIUM4.8A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
CVE-2022-47130MEDIUM4.3A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an...
CVE-2022-38389CRITICAL9.1IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2022-22486CRITICAL9.1IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2022-48114CRITICAL9.8RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
CVE-2022-48113CRITICAL9.8A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet servic...
CVE-2022-48140MEDIUM5.4DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view....
CVE-2022-48130CRITICAL9.8Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the para...
CVE-2022-48082CRITICAL9.8Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.as...
CVE-2022-48079CRITICAL9.8Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execu...
CVE-2022-46842HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.
CVE-2022-46815HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ...
CVE-2022-45807HIGH8.8Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.
CVE-2022-45067HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.
CVE-2022-44585HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
CVE-2022-40692HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.
CVE-2022-3560MEDIUM5.5A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service ...
CVE-2022-36401HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.
CVE-2022-46604HIGH8.8An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis...
CVE-2022-46552HIGH8.8D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan...
CVE-2022-46965HIGH8.8PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
CVE-2022-43665MEDIUM5.5A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-craft...
CVE-2022-2546MEDIUM4.7The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the r...
CVE-2022-40269HIGH8.1Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01...
CVE-2022-40268MEDIUM4.7Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT2...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now