2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41530 | HIGH | 7.2 | 0.8% | Oct 12, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at... |
| CVE-2022-41408 | CRITICAL | 9.8 | 0.6% | Oct 12, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page... |
| CVE-2022-41407 | HIGH | 7.2 | 0.8% | Oct 12, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page... |
| CVE-2022-41406 | HIGH | 7.2 | 1.0% | Oct 12, 2022 | An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows att... |
| CVE-2022-40921 | HIGH | 7.2 | 0.9% | Oct 12, 2022 | DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_con... |
| CVE-2022-40440 | MEDIUM | 6.1 | 0.7% | Oct 12, 2022 | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. |
| CVE-2022-28866 | HIGH | 8.8 | 1.0% | Oct 12, 2022 | Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not prope... |
| CVE-2022-42717 | HIGH | 7.8 | 0.2% | Oct 11, 2022 | An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is ... |
| CVE-2022-41404 | HIGH | 7.5 | 1.3% | Oct 11, 2022 | An issue in the fetch() method in the BasicProfile class of org.ini4j through version v0.5.4 allows attackers to cause a... |
| CVE-2022-40777 | HIGH | 8.8 | 0.9% | Oct 11, 2022 | Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit ... |
| CVE-2022-37617 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
| CVE-2022-42044 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir... |
| CVE-2022-42043 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third... |
| CVE-2022-42042 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by ... |
| CVE-2022-42041 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by... |
| CVE-2022-42040 | CRITICAL | 9.8 | 4.8% | Oct 11, 2022 | The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by ... |
| CVE-2022-42039 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thi... |
| CVE-2022-42038 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted b... |
| CVE-2022-42037 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir... |
| CVE-2022-42036 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir... |
| CVE-2022-41550 | MEDIUM | 6.5 | 0.5% | Oct 11, 2022 | GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. |
| CVE-2022-41387 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir... |
| CVE-2022-41386 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t... |
| CVE-2022-41385 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a thir... |
| CVE-2022-41384 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now