2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37202 | HIGH | 8.8 | 1.0% | Oct 26, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list |
| CVE-2022-3674 | CRITICAL | 9.8 | 0.5% | Oct 26, 2022 | A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected... |
| CVE-2022-3673 | MEDIUM | 6.1 | 0.3% | Oct 26, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Sanitization Management System 1.0. Af... |
| CVE-2022-3672 | MEDIUM | 6.1 | 0.3% | Oct 26, 2022 | A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1.... |
| CVE-2022-3671 | CRITICAL | 9.8 | 1.0% | Oct 26, 2022 | A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unkn... |
| CVE-2022-43766 | HIGH | 7.5 | 1.3% | Oct 26, 2022 | Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untr... |
| CVE-2022-42468 | CRITICAL | 9.8 | 2.7% | Oct 26, 2022 | Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration u... |
| CVE-2022-40238 | HIGH | 8.8 | 1.2% | Oct 26, 2022 | A Remote Code Injection vulnerability exists in CERT software prior to version 1.50.5. An authenticated attacker can inj... |
| CVE-2022-39944 | HIGH | 8.8 | 1.7% | Oct 26, 2022 | In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code... |
| CVE-2022-39357 | CRITICAL | 9.8 | 1.0% | Oct 26, 2022 | Winter is a free, open-source content management system based on the Laravel PHP framework. The Snowboard framework in v... |
| CVE-2022-20959 | MEDIUM | 5.4 | 0.8% | Oct 26, 2022 | A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow ... |
| CVE-2022-20955 | HIGH | 7.1 | 0.4% | Oct 26, 2022 | Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo... |
| CVE-2022-20954 | HIGH | 7.1 | 0.4% | Oct 26, 2022 | Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo... |
| CVE-2022-20953 | MEDIUM | 5.5 | 0.4% | Oct 26, 2022 | Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo... |
| CVE-2022-20933 | HIGH | 8.6 | 1.0% | Oct 26, 2022 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z3 Teleworker Gateway devices cou... |
| CVE-2022-20822 | HIGH | 8.1 | 1.2% | Oct 26, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20811 | HIGH | 7.2 | 0.7% | Oct 26, 2022 | Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo... |
| CVE-2022-20776 | MEDIUM | 6.7 | 0.5% | Oct 26, 2022 | Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo... |
| CVE-2022-43749 | HIGH | 8.8 | 0.6% | Oct 26, 2022 | Improper privilege management vulnerability in summary report management in Synology Presto File Server before 2.1.2-160... |
| CVE-2022-43748 | HIGH | 7.5 | 0.7% | Oct 26, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation managemen... |
| CVE-2022-2422 | CRITICAL | 9.8 | 0.7% | Oct 26, 2022 | Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the bac... |
| CVE-2022-2421 | CRITICAL | 9.8 | 1.1% | Oct 26, 2022 | Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeho... |
| CVE-2022-29823 | CRITICAL | 9.8 | 1.4% | Oct 26, 2022 | Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This... |
| CVE-2022-29822 | CRITICAL | 9.8 | 0.7% | Oct 26, 2022 | Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection |
| CVE-2022-31256 | HIGH | 7.8 | 0.2% | Oct 26, 2022 | A Improper Link Resolution Before File Access ('Link Following') vulnerability in a script called by the sendmail system... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now