2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42136HIGH8.8Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where...
CVE-2022-46956HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46955CRITICAL9.8Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46954CRITICAL9.8Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46953HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46952HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46951HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46950HIGH7.2Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46949HIGH7.2Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes...
CVE-2022-46947HIGH7.2Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes...
CVE-2022-46946HIGH7.2Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes...
CVE-2022-48091MEDIUM5.4Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
CVE-2022-48090MEDIUM6.5Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
CVE-2022-3693HIGH7.5Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue a...
CVE-2022-42268HIGH7.8 Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Mac...
CVE-2022-3841HIGH7.8RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the...
CVE-2022-3782CRITICAL9.1keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs...
CVE-2022-3143HIGH7.4wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elyt...
CVE-2022-21191CRITICAL9.8Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input saniti...
CVE-2022-42290HIGH8.8NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w...
CVE-2022-42289HIGH8.8NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w...
CVE-2022-42288MEDIUM5.3NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a v...
CVE-2022-42287HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary file...
CVE-2022-42286HIGH7.8DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of pr...
CVE-2022-46502CRITICAL9.8Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now