2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44120CRITICAL9.8dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
CVE-2022-44118CRITICAL9.8dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
CVE-2022-44117CRITICAL9.8Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa...
CVE-2022-43196CRITICAL9.1dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
CVE-2022-41933MEDIUM6.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset...
CVE-2022-41932MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t...
CVE-2022-45866MEDIUM5.3qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allow...
CVE-2022-44140HIGH8.8Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
CVE-2022-41946MEDIUM5.5pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStateme...
CVE-2022-41935MEDIUM4.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without t...
CVE-2022-41934HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with v...
CVE-2022-41931HIGH8.8xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injec...
CVE-2022-41930HIGH8.2org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged ...
CVE-2022-41929MEDIUM4.9org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorre...
CVE-2022-41928HIGH8.8XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in A...
CVE-2022-41927HIGH7.4XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags with...
CVE-2022-41925HIGH8.8A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be ...
CVE-2022-41924CRITICAL9.6A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo...
CVE-2022-41923CRITICAL9.8Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to...
CVE-2022-41875CRITICAL9.8A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via spe...
CVE-2022-41922CRITICAL9.8`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(...
CVE-2022-40772MEDIUM6.5Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to a...
CVE-2022-40771MEDIUM4.9Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads t...
CVE-2022-40304HIGH7.8An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, p...
CVE-2022-39833HIGH7.2FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and ac...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now