2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43179 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa... |
| CVE-2022-43163 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43162 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete... |
| CVE-2022-43142 | MEDIUM | 6.1 | 0.4% | Nov 17, 2022 | A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows atta... |
| CVE-2022-44403 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=. |
| CVE-2022-44402 | HIGH | 7.2 | 0.7% | Nov 17, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction. |
| CVE-2022-41920 | HIGH | 8.8 | 0.8% | Nov 17, 2022 | Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue wh... |
| CVE-2022-4053 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an... |
| CVE-2022-4052 | HIGH | 7.2 | 0.5% | Nov 17, 2022 | A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some un... |
| CVE-2022-4051 | CRITICAL | 9.8 | 0.6% | Nov 17, 2022 | A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknow... |
| CVE-2022-44384 | HIGH | 8.8 | 5.0% | Nov 17, 2022 | An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi... |
| CVE-2022-43140 | HIGH | 7.5 | 1.9% | Nov 17, 2022 | kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.control... |
| CVE-2022-43138 | CRITICAL | 9.8 | 1.2% | Nov 17, 2022 | Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. |
| CVE-2022-42894 | HIGH | 7.5 | 0.6% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Reques... |
| CVE-2022-42893 | HIGH | 7.5 | 0.5% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-42892 | MEDIUM | 5.3 | 0.6% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-42891 | HIGH | 7.5 | 0.5% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-42734 | HIGH | 7.5 | 0.5% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-42733 | HIGH | 7.5 | 0.6% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-42732 | HIGH | 7.5 | 0.6% | Nov 17, 2022 | A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos... |
| CVE-2022-40751 | MEDIUM | 4.9 | 0.6% | Nov 17, 2022 | IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 thr... |
| CVE-2022-38390 | MEDIUM | 5.4 | 0.4% | Nov 17, 2022 | Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows use... |
| CVE-2022-45461 | HIGH | 8.8 | 0.8% | Nov 17, 2022 | The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authentic... |
| CVE-2022-42985 | MEDIUM | 4.8 | 0.4% | Nov 17, 2022 | The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users w... |
| CVE-2022-42982 | HIGH | 7.5 | 0.7% | Nov 17, 2022 | BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now