2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-23050HIGH7.2ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hija...
CVE-2022-22977HIGH7.1VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious act...
CVE-2022-1669HIGH8.1A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The devi...
CVE-2022-22495HIGH8.8IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, w...
CVE-2022-29249HIGH7.5JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of loc...
CVE-2022-31261HIGH7.5An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML iden...
CVE-2022-30843HIGH8.8Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.
CVE-2022-29567HIGH7.5The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communica...
CVE-2022-29242HIGH7.5GOST engine is a reference implementation of the Russian GOST crypto algorithms for OpenSSL. TLS clients using GOST engi...
CVE-2022-29221HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2022-29219HIGH7.5Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a pos...
CVE-2022-29217HIGH7.5PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an att...
CVE-2022-1850HIGH8.1Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.
CVE-2022-30463HIGH8.8Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.
CVE-2022-30459HIGH8.8ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=del...
CVE-2022-26532HIGH7.8A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 t...
CVE-2022-26531HIGH7.8Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versio...
CVE-2022-1839HIGH8.8A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affect...
CVE-2022-1838HIGH7.2A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn...
CVE-2022-1837HIGH7.2A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this ...
CVE-2022-29309HIGH7.5mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
CVE-2022-29305HIGH8.1imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
CVE-2022-29377HIGH7.5Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.c...
CVE-2022-29376HIGH8.8Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at...
CVE-2022-29002HIGH8.8A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now