2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43179HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?pa...
CVE-2022-43163HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43162HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43142MEDIUM6.1A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows atta...
CVE-2022-44403HIGH7.2Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.
CVE-2022-44402HIGH7.2Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.
CVE-2022-41920HIGH8.8Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue wh...
CVE-2022-4053MEDIUM4.8A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an...
CVE-2022-4052HIGH7.2A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some un...
CVE-2022-4051CRITICAL9.8A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknow...
CVE-2022-44384HIGH8.8An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi...
CVE-2022-43140HIGH7.5kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.control...
CVE-2022-43138CRITICAL9.8Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
CVE-2022-42894HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Reques...
CVE-2022-42893HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42892MEDIUM5.3A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42891HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42734HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42733HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42732HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-40751MEDIUM4.9 IBM UrbanCode Deploy (UCD) 6.2.7.0 through 6.2.7.17, 7.0.0.0 through 7.0.5.12, 7.1.0.0 through 7.1.2.8, and 7.2.0.0 thr...
CVE-2022-38390MEDIUM5.4Multiple IBM Business Automation Workflow versions are vulnerable to cross-site scripting. This vulnerability allows use...
CVE-2022-45461HIGH8.8The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authentic...
CVE-2022-42985MEDIUM4.8The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users w...
CVE-2022-42982HIGH7.5BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now