2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42954MEDIUM5.4Keyfactor EJBCA before 7.10.0 allows XSS.
CVE-2022-39834MEDIUM5.4A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-priv...
CVE-2022-36432MEDIUM5.4The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers t...
CVE-2022-42246HIGH8.8Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
CVE-2022-42245CRITICAL9.8Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
CVE-2022-42187MEDIUM6.1Hustoj 22.09.22 has a XSS Vulnerability in /admin/problem_judge.php.
CVE-2022-40881CRITICAL9.8SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
CVE-2022-43782CRITICAL9.8Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfigur...
CVE-2022-43781CRITICAL9.8There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker ...
CVE-2022-42960MEDIUM5.4EqualWeb Accessibility Widget 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.10, 3.0.0, 3.0.1, 3.0.2, 4.0.0, and 4.0.1 allows DO...
CVE-2022-44006CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames...
CVE-2022-44005MEDIUM5.3An issue was discovered in BACKCLICK Professional 5.9.63. Due to the use of consecutive IDs in verification links, the n...
CVE-2022-44004CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica...
CVE-2022-44003CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli...
CVE-2022-44002MEDIUM6.1An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient output encoding of user-supplied data, the...
CVE-2022-44000CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos...
CVE-2022-40752CRITICAL9.8IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci...
CVE-2022-44008MEDIUM6.5An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retri...
CVE-2022-44007HIGH8.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is pos...
CVE-2022-43999CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com...
CVE-2022-39319MEDIUM4.6FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length val...
CVE-2022-39318MEDIUM5.7FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation...
CVE-2022-39317MEDIUM4.6FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check fo...
CVE-2022-43135CRITICAL9.8Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa...
CVE-2022-41914LOW3.7Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now