2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44204 | CRITICAL | 9.8 | 1.2% | Nov 18, 2022 | D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow. |
| CVE-2022-39180 | CRITICAL | 9.8 | 0.6% | Nov 17, 2022 | College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in... |
| CVE-2022-38165 | CRITICAL | 9.8 | 0.8% | Nov 17, 2022 | Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with t... |
| CVE-2022-36787 | CRITICAL | 9.8 | 0.6% | Nov 17, 2022 | webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/... |
| CVE-2022-36786 | CRITICAL | 9.9 | 0.9% | Nov 17, 2022 | DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network ... |
| CVE-2022-36784 | CRITICAL | 9.8 | 1.1% | Nov 17, 2022 | Elsight – Elsight Halo Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. ... |
| CVE-2022-44001 | CRITICAL | 9.8 | 1.1% | Nov 17, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services ... |
| CVE-2022-4051 | CRITICAL | 9.8 | 0.6% | Nov 17, 2022 | A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknow... |
| CVE-2022-43138 | CRITICAL | 9.8 | 1.2% | Nov 17, 2022 | Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API. |
| CVE-2022-42245 | CRITICAL | 9.8 | 0.8% | Nov 17, 2022 | Dreamer CMS 4.0.01 is vulnerable to SQL Injection. |
| CVE-2022-40881 | CRITICAL | 9.8 | 29.5% | Nov 17, 2022 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php |
| CVE-2022-43782 | CRITICAL | 9.8 | 0.9% | Nov 17, 2022 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfigur... |
| CVE-2022-43781 | CRITICAL | 9.8 | 98.0% | Nov 17, 2022 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker ... |
| CVE-2022-44006 | CRITICAL | 9.8 | 1.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames... |
| CVE-2022-44004 | CRITICAL | 9.8 | 1.2% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthentica... |
| CVE-2022-44003 | CRITICAL | 9.8 | 1.5% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the appli... |
| CVE-2022-44000 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is pos... |
| CVE-2022-40752 | CRITICAL | 9.8 | 1.8% | Nov 16, 2022 | IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of speci... |
| CVE-2022-43999 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system com... |
| CVE-2022-43135 | CRITICAL | 9.8 | 0.8% | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username pa... |
| CVE-2022-43262 | CRITICAL | 9.8 | 0.8% | Nov 16, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter... |
| CVE-2022-43256 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i... |
| CVE-2022-43234 | CRITICAL | 9.8 | 0.9% | Nov 16, 2022 | An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary... |
| CVE-2022-3980 | CRITICAL | 9.8 | 8.1% | Nov 16, 2022 | An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sop... |
| CVE-2022-45047 | CRITICAL | 9.8 | 3.6% | Nov 16, 2022 | Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now