2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43449MEDIUM5.5OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ...
CVE-2022-43063HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43062HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43061HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co...
CVE-2022-42749MEDIUM6.1CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitra...
CVE-2022-42748MEDIUM6.1CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie o...
CVE-2022-42747MEDIUM6.1CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbit...
CVE-2022-42746MEDIUM6.1CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of ar...
CVE-2022-42745HIGH7.5CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because th...
CVE-2022-42744CRITICAL9.8CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos...
CVE-2022-42743MEDIUM5.3deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible b...
CVE-2022-42442LOW3.3 IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of th...
CVE-2022-41714MEDIUM5.3fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible...
CVE-2022-41713MEDIUM5.3deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible ...
CVE-2022-41710MEDIUM5.5Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp...
CVE-2022-40747CRITICAL9.1"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X...
CVE-2022-40276MEDIUM5.5Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to...
CVE-2022-40235MEDIUM6.5"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run j...
CVE-2022-40230MEDIUM6.5"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an aut...
CVE-2022-40131MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an...
CVE-2022-38712MEDIUM5.9"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc...
CVE-2022-38710MEDIUM5.3IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info...
CVE-2022-36428MEDIUM4.8Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.
CVE-2022-36404MEDIUM5.4Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugi...
CVE-2022-35717HIGH7.8"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on th...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now