2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37202HIGH8.8JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
CVE-2022-3674CRITICAL9.8A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected...
CVE-2022-3673MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Sanitization Management System 1.0. Af...
CVE-2022-3672MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1....
CVE-2022-3671CRITICAL9.8A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unkn...
CVE-2022-43766HIGH7.5Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untr...
CVE-2022-42468CRITICAL9.8Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u...
CVE-2022-40238HIGH8.8A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inj...
CVE-2022-39944HIGH8.8In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code...
CVE-2022-39357CRITICAL9.8Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in v...
CVE-2022-20959MEDIUM5.4A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow ...
CVE-2022-20955HIGH7.1Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo...
CVE-2022-20954HIGH7.1Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo...
CVE-2022-20953MEDIUM5.5Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo...
CVE-2022-20933HIGH8.6A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices cou...
CVE-2022-20822HIGH8.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2022-20811HIGH7.2Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo...
CVE-2022-20776MEDIUM6.7Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo...
CVE-2022-43749HIGH8.8Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-160...
CVE-2022-43748HIGH7.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation managemen...
CVE-2022-2422CRITICAL9.8Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the bac...
CVE-2022-2421CRITICAL9.8Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeho...
CVE-2022-29823CRITICAL9.8Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This...
CVE-2022-29822CRITICAL9.8Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection
CVE-2022-31256HIGH7.8A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail system...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now