2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40673HIGH7.8KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
CVE-2022-40626MEDIUM6.1An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to oth...
CVE-2022-37140HIGH8PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket func...
CVE-2022-37139MEDIUM5.4Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
CVE-2022-37138CRITICAL9.8Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as...
CVE-2022-37137MEDIUM5.4PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from i...
CVE-2022-36669CRITICAL9.8Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication...
CVE-2022-36668MEDIUM5.4Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabiliti...
CVE-2022-36667HIGH8.8Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file...
CVE-2022-36436CRITICAL9.8OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentica...
CVE-2022-2900CRITICAL9.1Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.
CVE-2022-34831CRITICAL9.8An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers...
CVE-2022-38771CRITICAL9.8The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tag...
CVE-2022-38770MEDIUM5.3The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other use...
CVE-2022-38769HIGH7.5The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext...
CVE-2022-38768CRITICAL9.8The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authoriz...
CVE-2022-38305HIGH8.8AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. Th...
CVE-2022-37191MEDIUM6.5The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v...
CVE-2022-37190HIGH8.8CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and...
CVE-2022-38633HIGH7.8Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate pri...
CVE-2022-35582HIGH8.8Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating sy...
CVE-2022-35413CRITICAL9.8WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configur...
CVE-2022-34102HIGH8.8Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39,...
CVE-2022-34101HIGH7.8A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place...
CVE-2022-31861MEDIUM5.4Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now