2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1471CRITICAL9.8SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing ...
CVE-2022-4221CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25...
CVE-2022-45050MEDIUM6.1A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's br...
CVE-2022-4253MEDIUM5.4A vulnerability was found in SourceCodester Canteen Management System. It has been declared as problematic. This vulnera...
CVE-2022-4252MEDIUM6.1A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec...
CVE-2022-4251MEDIUM5.4A vulnerability was found in Movie Ticket Booking System and classified as problematic. Affected by this issue is some u...
CVE-2022-4250MEDIUM6.1A vulnerability has been found in Movie Ticket Booking System and classified as problematic. Affected by this vulnerabil...
CVE-2022-4249MEDIUM6.1A vulnerability, which was classified as problematic, was found in Movie Ticket Booking System. Affected is an unknown f...
CVE-2022-4248CRITICAL9.8A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects som...
CVE-2022-4247CRITICAL9.8A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code...
CVE-2022-4246HIGH7.5A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the compone...
CVE-2022-36431CRITICAL9.8An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to...
CVE-2022-45640HIGH7.5Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).
CVE-2022-45045HIGH8.8Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C74311...
CVE-2022-44262CRITICAL9.8ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
CVE-2022-40849MEDIUM5.4ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vul...
CVE-2022-40489HIGH8.8ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrato...
CVE-2022-40204MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via t...
CVE-2022-46162CRITICAL9.8discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rend...
CVE-2022-46156LOW3.3The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes ...
CVE-2022-23746HIGH7.5The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the por...
CVE-2022-44296HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.
CVE-2022-44295HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.
CVE-2022-44294HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.
CVE-2022-4234MEDIUM6.1A vulnerability was found in SourceCodester Canteen Management System. It has been rated as problematic. This issue affe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now