2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39346 | MEDIUM | 6.5 | 1.0% | Nov 25, 2022 | Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u... |
| CVE-2022-39339 | MEDIUM | 4.3 | 0.4% | Nov 25, 2022 | user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the ... |
| CVE-2022-39338 | MEDIUM | 5.4 | 0.6% | Nov 25, 2022 | user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery u... |
| CVE-2022-39334 | MEDIUM | 4.7 | 0.2% | Nov 25, 2022 | Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv... |
| CVE-2022-39331 | MEDIUM | 5.4 | 0.9% | Nov 25, 2022 | Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in... |
| CVE-2022-45476 | CRITICAL | 9.8 | 1.0% | Nov 25, 2022 | Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni... |
| CVE-2022-45475 | MEDIUM | 6.5 | 0.8% | Nov 25, 2022 | Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. Th... |
| CVE-2022-44860 | HIGH | 7.2 | 0.7% | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-44859 | HIGH | 7.2 | 0.7% | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-44858 | HIGH | 7.2 | 0.8% | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-41958 | HIGH | 7.8 | 0.4% | Nov 25, 2022 | super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config whic... |
| CVE-2022-41712 | MEDIUM | 6.5 | 0.9% | Nov 25, 2022 | Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because th... |
| CVE-2022-41706 | HIGH | 8.2 | 0.6% | Nov 25, 2022 | Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus... |
| CVE-2022-41705 | CRITICAL | 9.8 | 1.8% | Nov 25, 2022 | Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is... |
| CVE-2022-0698 | MEDIUM | 6.1 | 0.7% | Nov 25, 2022 | Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' p... |
| CVE-2022-45218 | MEDIUM | 6.1 | 0.4% | Nov 25, 2022 | Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulne... |
| CVE-2022-45210 | MEDIUM | 4.3 | 0.5% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin. |
| CVE-2022-45208 | MEDIUM | 4.3 | 0.5% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin. |
| CVE-2022-45207 | CRITICAL | 9.8 | 0.9% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString. |
| CVE-2022-45206 | CRITICAL | 9.8 | 0.8% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check. |
| CVE-2022-45205 | MEDIUM | 5.3 | 0.6% | Nov 25, 2022 | Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. |
| CVE-2022-43984 | HIGH | 8.2 | 0.6% | Nov 25, 2022 | Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus... |
| CVE-2022-43983 | HIGH | 8.2 | 0.6% | Nov 25, 2022 | Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus... |
| CVE-2022-38813 | HIGH | 8.1 | 1.5% | Nov 25, 2022 | PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows atta... |
| CVE-2022-37721 | CRITICAL | 9 | 0.7% | Nov 25, 2022 | PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now