2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36431 | CRITICAL | 9.8 | 1.1% | Dec 1, 2022 | An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to... |
| CVE-2022-44262 | CRITICAL | 9.8 | 1.5% | Dec 1, 2022 | ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE). |
| CVE-2022-46162 | CRITICAL | 9.8 | 1.1% | Nov 30, 2022 | discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend... |
| CVE-2022-44151 | CRITICAL | 9.8 | 0.9% | Nov 30, 2022 | Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. |
| CVE-2022-44136 | CRITICAL | 9.8 | 1.1% | Nov 30, 2022 | Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). |
| CVE-2022-4232 | CRITICAL | 9.8 | 0.4% | Nov 30, 2022 | A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected i... |
| CVE-2022-4229 | CRITICAL | 9.8 | 0.9% | Nov 30, 2022 | A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability ... |
| CVE-2022-4222 | CRITICAL | 9.8 | 0.7% | Nov 30, 2022 | A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects... |
| CVE-2022-44097 | CRITICAL | 9.8 | 0.8% | Nov 30, 2022 | Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate pri... |
| CVE-2022-44096 | CRITICAL | 9.8 | 0.8% | Nov 30, 2022 | Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate p... |
| CVE-2022-3751 | CRITICAL | 9.8 | 0.9% | Nov 29, 2022 | SQL Injection in GitHub repository owncast/owncast prior to 0.0.13. |
| CVE-2022-44354 | CRITICAL | 9.8 | 2.1% | Nov 29, 2022 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. |
| CVE-2022-44038 | CRITICAL | 9.8 | 1.6% | Nov 29, 2022 | Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunn... |
| CVE-2022-42109 | CRITICAL | 9.8 | 1.1% | Nov 29, 2022 | Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop... |
| CVE-2022-44399 | CRITICAL | 9.8 | 0.8% | Nov 28, 2022 | Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/c... |
| CVE-2022-44401 | CRITICAL | 9.8 | 0.9% | Nov 28, 2022 | Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. |
| CVE-2022-44400 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. |
| CVE-2022-44283 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | AVS Audio Converter 10.3 is vulnerable to Buffer Overflow. |
| CVE-2022-41912 | CRITICAL | 9.8 | 2.2% | Nov 28, 2022 | The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML respon... |
| CVE-2022-3603 | CRITICAL | 9.8 | 1.1% | Nov 28, 2022 | The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2... |
| CVE-2022-36193 | CRITICAL | 9.8 | 1.4% | Nov 28, 2022 | SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent chang... |
| CVE-2022-43705 | CRITICAL | 9.1 | 0.4% | Nov 27, 2022 | In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was i... |
| CVE-2022-45933 | CRITICAL | 9.8 | 51.7% | Nov 27, 2022 | KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n... |
| CVE-2022-45909 | CRITICAL | 9.1 | 1.0% | Nov 26, 2022 | drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request. |
| CVE-2022-45908 | CRITICAL | 9.8 | 1.3% | Nov 26, 2022 | In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now