2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39346MEDIUM6.5Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u...
CVE-2022-39339MEDIUM4.3user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the ...
CVE-2022-39338MEDIUM5.4user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery u...
CVE-2022-39334MEDIUM4.7Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv...
CVE-2022-39331MEDIUM5.4Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-45476CRITICAL9.8Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni...
CVE-2022-45475MEDIUM6.5Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. Th...
CVE-2022-44860HIGH7.2Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-44859HIGH7.2Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-44858HIGH7.2Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-41958HIGH7.8super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config whic...
CVE-2022-41712MEDIUM6.5Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because th...
CVE-2022-41706HIGH8.2Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus...
CVE-2022-41705CRITICAL9.8Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is...
CVE-2022-0698MEDIUM6.1Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' p...
CVE-2022-45218MEDIUM6.1Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulne...
CVE-2022-45210MEDIUM4.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
CVE-2022-45208MEDIUM4.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
CVE-2022-45207CRITICAL9.8Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
CVE-2022-45206CRITICAL9.8Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
CVE-2022-45205MEDIUM5.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-43984HIGH8.2Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus...
CVE-2022-43983HIGH8.2Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible becaus...
CVE-2022-38813HIGH8.1PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows atta...
CVE-2022-37721CRITICAL9PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now