2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-28016HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\dedu...
CVE-2022-28015HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash...
CVE-2022-28014HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte...
CVE-2022-28013HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche...
CVE-2022-28012HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi...
CVE-2022-28011HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche...
CVE-2022-28010HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over...
CVE-2022-28009HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte...
CVE-2022-28008HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\atte...
CVE-2022-28007HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cash...
CVE-2022-28006HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl...
CVE-2022-27478HIGH8.8Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?se...
CVE-2022-29566HIGH8.1The Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation because the hash computation fails to include all of ...
CVE-2022-20795HIGH7.5A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Sof...
CVE-2022-20786HIGH8.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service ...
CVE-2022-20783HIGH7.5A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Ci...
CVE-2022-20773HIGH7.5A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an un...
CVE-2022-20732HIGH7.8A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an a...
CVE-2022-24875HIGH7.5The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and includ...
CVE-2022-24867HIGH7.5GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-29498HIGH7.5Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they wou...
CVE-2022-29547HIGH7.5The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to...
CVE-2022-27925HIGH7.2Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file...
CVE-2022-27924HIGH7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands i...
CVE-2022-29536HIGH7.5In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_strin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now