2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39035MEDIUM6.1Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An ...
CVE-2022-39034MEDIUM6.5Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special ch...
CVE-2022-39033CRITICAL9.8Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c...
CVE-2022-39032HIGH8.8Smart eVision has an improper privilege management vulnerability. A remote attacker with general user privilege can expl...
CVE-2022-39031MEDIUM5.3Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit ...
CVE-2022-39030HIGH7.5smart eVision has inadequate authorization for system information query function. An unauthenticated remote attacker, wh...
CVE-2022-39029MEDIUM6.5Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg...
CVE-2022-38699MEDIUM5.9Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A phys...
CVE-2022-40497HIGH8.8Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code exe...
CVE-2022-41604HIGH8.8Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs beca...
CVE-2022-41571CRITICAL9.8An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
CVE-2022-41570CRITICAL9.8An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.
CVE-2022-40878HIGH8.8In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to ach...
CVE-2022-40877CRITICAL9.8Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
CVE-2022-40817MEDIUM4.3Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents w...
CVE-2022-40816MEDIUM6.5Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that custo...
CVE-2022-40354HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40353HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40352HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40199LOW2.7Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 ...
CVE-2022-3324HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
CVE-2022-3323HIGH7.5An SQL injection vulnerability in Advantech iView 5.7.04.6469. The specific flaw exists within the ConfigurationServlet ...
CVE-2022-3303MEDIUM4.7A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL poi...
CVE-2022-39835MEDIUM5.3An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct ...
CVE-2022-38975MEDIUM5.4DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to in...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now