2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30820HIGH8.8In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.p...
CVE-2022-30819HIGH8.8In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photo...
CVE-2022-30818HIGH7.2Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.
CVE-2022-30799HIGH7.2Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
CVE-2022-30798HIGH7.2Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
CVE-2022-30795HIGH7.2Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
CVE-2022-30794HIGH7.2Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
CVE-2022-30540HIGH7.8The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacke...
CVE-2022-30496HIGH7.5SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user...
CVE-2022-30425HIGH8.8Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr a...
CVE-2022-30034HIGH8.6Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentica...
CVE-2022-29735HIGH8.8Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a craf...
CVE-2022-29729HIGH7.5Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which...
CVE-2022-29725HIGH8.8An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via ...
CVE-2022-29695HIGH7.5Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
CVE-2022-29694HIGH7.5Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.
CVE-2022-29693HIGH7.5Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc....
CVE-2022-29692HIGH7.8Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.
CVE-2022-29647HIGH8.8An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/...
CVE-2022-29624HIGH8.8An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code...
CVE-2022-29488HIGH7.8The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to ex...
CVE-2022-29483HIGH7.8Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with...
CVE-2022-28799HIGH8.8The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force...
CVE-2022-28690HIGH7.8The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to e...
CVE-2022-27782HIGH7.5libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should ha...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now