2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-44204CRITICAL9.8D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.
CVE-2022-39180CRITICAL9.8 College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in...
CVE-2022-38165CRITICAL9.8Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with t...
CVE-2022-36787CRITICAL9.8 webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/...
CVE-2022-36786CRITICAL9.9DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network ...
CVE-2022-36784CRITICAL9.8 Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. ...
CVE-2022-44001CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services ...
CVE-2022-4051CRITICAL9.8A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknow...
CVE-2022-43138CRITICAL9.8Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
CVE-2022-42245CRITICAL9.8Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
CVE-2022-40881CRITICAL9.8SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
CVE-2022-43782CRITICAL9.8Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfigur...
CVE-2022-43781CRITICAL9.8There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker ...
CVE-2022-44006CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames...
CVE-2022-44004CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica...
CVE-2022-44003CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli...
CVE-2022-44000CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos...
CVE-2022-40752CRITICAL9.8IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci...
CVE-2022-43999CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com...
CVE-2022-43135CRITICAL9.8Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa...
CVE-2022-43262CRITICAL9.8Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter...
CVE-2022-43256CRITICAL9.8SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i...
CVE-2022-43234CRITICAL9.8An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary...
CVE-2022-3980CRITICAL9.8An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sop...
CVE-2022-45047CRITICAL9.8Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now