2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46476CRITICAL9.8D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soap...
CVE-2022-31901MEDIUM6.5Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the appli...
CVE-2022-47766HIGH8.8PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
CVE-2022-46890MEDIUM4.3Weak access control in NexusPHP before 1.7.33 allows a remote authenticated user to edit any post in the forum (this is ...
CVE-2022-46889MEDIUM5.4A persistent cross-site scripting (XSS) vulnerability in NexusPHP before 1.7.33 allows remote authenticated attackers to...
CVE-2022-46888MEDIUM6.1Multiple reflective cross-site scripting (XSS) vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to injec...
CVE-2022-46887CRITICAL9.8Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL command...
CVE-2022-47745HIGH8.8ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection...
CVE-2022-47740CRITICAL9.8Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
CVE-2022-47197MEDIUM5.4An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default ins...
CVE-2022-47196MEDIUM5.4An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default ins...
CVE-2022-47195MEDIUM5.4An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default ins...
CVE-2022-47194MEDIUM5.4An insecure default vulnerability exists in the Post Creation functionality of Ghost Foundation Ghost 5.9.4. Default ins...
CVE-2022-40697MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugi...
CVE-2022-39167MEDIUM5.9 IBM Spectrum Virtualize 8.5, 8.4, 8.3, 8.2, and 7.8, under certain configurations, could disclose sensitive information...
CVE-2022-1676Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-47105CRITICAL9.8Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-3738MEDIUM5.9The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file mi...
CVE-2022-4892MEDIUM6.1A vulnerability was found in MyCMS. It has been classified as problematic. This affects the function build_view of the f...
CVE-2022-3085HIGH7.8 Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to a stack-based buffer overflow which...
CVE-2022-4235MEDIUM5.4RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious applicatio...
CVE-2022-45927HIGH8.8An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used ...
CVE-2022-45923HIGH8.8An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) progr...
CVE-2022-45928HIGH8.8A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoin...
CVE-2022-45926HIGH8.8An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplat...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now