2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24232 | HIGH | 7.8 | 1.4% | Feb 24, 2022 | A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via ... |
| CVE-2022-23922 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file... |
| CVE-2022-23104 | HIGH | 7.8 | 0.2% | Feb 24, 2022 | WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file... |
| CVE-2022-21824 | HIGH | 8.2 | 21.5% | Feb 24, 2022 | Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passe... |
| CVE-2022-0651 | HIGH | 7.5 | 33.0% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
| CVE-2022-0546 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing a... |
| CVE-2022-0545 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds... |
| CVE-2022-22793 | HIGH | 7.5 | 0.7% | Feb 24, 2022 | Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer... |
| CVE-2022-24707 | HIGH | 8.8 | 7.2% | Feb 24, 2022 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-b... |
| CVE-2022-0732 | HIGH | 7.5 | 2.5% | Feb 24, 2022 | The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth... |
| CVE-2022-25838 | HIGH | 8.1 | 0.9% | Feb 24, 2022 | Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "... |
| CVE-2022-25640 | HIGH | 7.5 | 1.3% | Feb 24, 2022 | In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can ... |
| CVE-2022-25636 | HIGH | 7.8 | 2.6% | Feb 24, 2022 | net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a ... |
| CVE-2022-25401 | HIGH | 7.5 | 2.2% | Feb 24, 2022 | The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting ... |
| CVE-2022-25360 | HIGH | 8.8 | 1.3% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload fil... |
| CVE-2022-25293 | HIGH | 8.8 | 2.0% | Feb 24, 2022 | A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t... |
| CVE-2022-25292 | HIGH | 8.8 | 2.0% | Feb 24, 2022 | A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t... |
| CVE-2022-25291 | HIGH | 8.8 | 1.7% | Feb 24, 2022 | An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-b... |
| CVE-2022-25104 | HIGH | 7.5 | 1.1% | Feb 24, 2022 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/fi... |
| CVE-2022-25101 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code vi... |
| CVE-2022-25099 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via ... |
| CVE-2022-24610 | HIGH | 8.6 | 0.9% | Feb 24, 2022 | Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi ... |
| CVE-2022-24407 | HIGH | 8.8 | 4.1% | Feb 24, 2022 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE... |
| CVE-2022-23986 | HIGH | 7.5 | 1.7% | Feb 24, 2022 | SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the i... |
| CVE-2022-23176 | HIGH | 8.8 | 12.2% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now