2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-41497CRITICAL9.8ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/in...
CVE-2022-41496CRITICAL9.8iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
CVE-2022-41495CRITICAL9.8ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manag...
CVE-2022-3457CRITICAL9.8Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.
CVE-2022-3456CRITICAL9.8Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-39293CRITICAL9.8Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated wit...
CVE-2022-42889CRITICAL9.8Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The s...
CVE-2022-24697CRITICAL9.8Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configura...
CVE-2022-42897CRITICAL9.8Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege...
CVE-2022-39298CRITICAL9.8MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewri...
CVE-2022-39297CRITICAL9.8MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many admin...
CVE-2022-37601CRITICAL9.8Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable ...
CVE-2022-31228CRITICAL9.8Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can...
CVE-2022-41403CRITICAL9.8OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at ...
CVE-2022-3467CRITICAL9.8A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality...
CVE-2022-33106CRITICAL9.8WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force...
CVE-2022-40871CRITICAL9.8Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installat...
CVE-2022-37614CRITICAL9.8Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5c...
CVE-2022-3465CRITICAL9.8A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of th...
CVE-2022-40664CRITICAL9.8Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatc...
CVE-2022-3458CRITICAL9.8A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect...
CVE-2022-42711CRITICAL9.6In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious ...
CVE-2022-37611CRITICAL9.8Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
CVE-2022-41408CRITICAL9.8Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page...
CVE-2022-37617CRITICAL9.8Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now