2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30238HIGH8.8A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when...
CVE-2022-30237HIGH7.5A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be r...
CVE-2022-30236HIGH8.2A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an...
CVE-2022-30232HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attack...
CVE-2022-29594HIGH7.8eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
CVE-2022-31463HIGH7.1Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authenticatio...
CVE-2022-31462HIGH8.8Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial nu...
CVE-2022-31460HIGH7.4Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a cer...
CVE-2022-32250HIGH7.8net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces...
CVE-2022-26868HIGH7.8Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated ...
CVE-2022-26867HIGH8PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, with...
CVE-2022-22557HIGH7.8PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x ...
CVE-2022-22556HIGH7.5Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unaut...
CVE-2022-31023HIGH7.5Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error mess...
CVE-2022-31018HIGH7.5Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2...
CVE-2022-32028HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php...
CVE-2022-32027HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=...
CVE-2022-32026HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking....
CVE-2022-32025HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id...
CVE-2022-32024HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.
CVE-2022-32022HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?act...
CVE-2022-32021HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement...
CVE-2022-32018HIGH7.2Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.
CVE-2022-32017HIGH7.2Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle.
CVE-2022-32016HIGH7.2Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now