2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23520 | MEDIUM | 6.1 | 1.1% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there i... |
| CVE-2022-46127 | HIGH | 7.2 | 0.8% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product. |
| CVE-2022-46126 | HIGH | 7.2 | 0.8% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=. |
| CVE-2022-46125 | HIGH | 7.2 | 0.8% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=. |
| CVE-2022-46124 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=. |
| CVE-2022-46123 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=. |
| CVE-2022-46122 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/view_category.php?id=. |
| CVE-2022-46121 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/manage_product&id=. |
| CVE-2022-46120 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=products/view_product&id=. |
| CVE-2022-46119 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=categories&c=. |
| CVE-2022-46118 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=product_per_brand&bid=. |
| CVE-2022-46117 | HIGH | 7.2 | 0.7% | Dec 14, 2022 | Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=. |
| CVE-2022-46074 | HIGH | 8.8 | 0.5% | Dec 14, 2022 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin a... |
| CVE-2022-46073 | MEDIUM | 6.1 | 1.2% | Dec 14, 2022 | Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-23519 | MEDIUM | 6.1 | 1.0% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possi... |
| CVE-2022-23518 | MEDIUM | 6.1 | 0.9% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are ... |
| CVE-2022-23517 | HIGH | 7.5 | 1.5% | Dec 14, 2022 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails... |
| CVE-2022-4495 | MEDIUM | 6.1 | 0.5% | Dec 14, 2022 | A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue... |
| CVE-2022-46997 | CRITICAL | 9.8 | 1.1% | Dec 14, 2022 | Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the req... |
| CVE-2022-46996 | CRITICAL | 9.8 | 1.3% | Dec 14, 2022 | vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via ... |
| CVE-2022-46609 | CRITICAL | 9.8 | 1.4% | Dec 14, 2022 | Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was disc... |
| CVE-2022-44898 | HIGH | 7.8 | 0.4% | Dec 14, 2022 | The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x8010... |
| CVE-2022-44832 | CRITICAL | 9.8 | 3.9% | Dec 14, 2022 | D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTrigg... |
| CVE-2022-31358 | CRITICAL | 9 | 1.3% | Dec 14, 2022 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attack... |
| CVE-2022-23516 | HIGH | 7.5 | 1.1% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now