2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41497 | CRITICAL | 9.8 | 0.9% | Oct 13, 2022 | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/in... |
| CVE-2022-41496 | CRITICAL | 9.8 | 0.9% | Oct 13, 2022 | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. |
| CVE-2022-41495 | CRITICAL | 9.8 | 0.9% | Oct 13, 2022 | ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manag... |
| CVE-2022-3457 | CRITICAL | 9.8 | 0.3% | Oct 13, 2022 | Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5. |
| CVE-2022-3456 | CRITICAL | 9.8 | 0.3% | Oct 13, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0. |
| CVE-2022-39293 | CRITICAL | 9.8 | 0.6% | Oct 13, 2022 | Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated wit... |
| CVE-2022-42889 | CRITICAL | 9.8 | 99.9% | Oct 13, 2022 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The s... |
| CVE-2022-24697 | CRITICAL | 9.8 | 84.8% | Oct 13, 2022 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configura... |
| CVE-2022-42897 | CRITICAL | 9.8 | 1.5% | Oct 13, 2022 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege... |
| CVE-2022-39298 | CRITICAL | 9.8 | 0.9% | Oct 12, 2022 | MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewri... |
| CVE-2022-39297 | CRITICAL | 9.8 | 0.9% | Oct 12, 2022 | MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many admin... |
| CVE-2022-37601 | CRITICAL | 9.8 | 2.6% | Oct 12, 2022 | Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable ... |
| CVE-2022-31228 | CRITICAL | 9.8 | 0.7% | Oct 12, 2022 | Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can... |
| CVE-2022-41403 | CRITICAL | 9.8 | 1.1% | Oct 12, 2022 | OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at ... |
| CVE-2022-3467 | CRITICAL | 9.8 | 0.5% | Oct 12, 2022 | A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality... |
| CVE-2022-33106 | CRITICAL | 9.8 | 0.8% | Oct 12, 2022 | WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force... |
| CVE-2022-40871 | CRITICAL | 9.8 | 33.4% | Oct 12, 2022 | Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installat... |
| CVE-2022-37614 | CRITICAL | 9.8 | 1.2% | Oct 12, 2022 | Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5c... |
| CVE-2022-3465 | CRITICAL | 9.8 | 0.8% | Oct 12, 2022 | A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of th... |
| CVE-2022-40664 | CRITICAL | 9.8 | 2.2% | Oct 12, 2022 | Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatc... |
| CVE-2022-3458 | CRITICAL | 9.8 | 0.4% | Oct 12, 2022 | A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect... |
| CVE-2022-42711 | CRITICAL | 9.6 | 1.0% | Oct 12, 2022 | In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious ... |
| CVE-2022-37611 | CRITICAL | 9.8 | 1.0% | Oct 12, 2022 | Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js. |
| CVE-2022-41408 | CRITICAL | 9.8 | 0.6% | Oct 12, 2022 | Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page... |
| CVE-2022-37617 | CRITICAL | 9.8 | 1.2% | Oct 11, 2022 | Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now