2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40673 | HIGH | 7.8 | 0.4% | Sep 14, 2022 | KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. |
| CVE-2022-40626 | MEDIUM | 6.1 | 0.7% | Sep 14, 2022 | An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to oth... |
| CVE-2022-37140 | HIGH | 8 | 1.3% | Sep 14, 2022 | PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket func... |
| CVE-2022-37139 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability. |
| CVE-2022-37138 | CRITICAL | 9.8 | 1.0% | Sep 14, 2022 | Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as... |
| CVE-2022-37137 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from i... |
| CVE-2022-36669 | CRITICAL | 9.8 | 2.1% | Sep 14, 2022 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication... |
| CVE-2022-36668 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabiliti... |
| CVE-2022-36667 | HIGH | 8.8 | 24.4% | Sep 14, 2022 | Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file... |
| CVE-2022-36436 | CRITICAL | 9.8 | 1.7% | Sep 14, 2022 | OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentica... |
| CVE-2022-2900 | CRITICAL | 9.1 | 0.9% | Sep 14, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0. |
| CVE-2022-34831 | CRITICAL | 9.8 | 0.4% | Sep 14, 2022 | An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers... |
| CVE-2022-38771 | CRITICAL | 9.8 | 1.0% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tag... |
| CVE-2022-38770 | MEDIUM | 5.3 | 0.6% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other use... |
| CVE-2022-38769 | HIGH | 7.5 | 0.8% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext... |
| CVE-2022-38768 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authoriz... |
| CVE-2022-38305 | HIGH | 8.8 | 0.9% | Sep 13, 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. Th... |
| CVE-2022-37191 | MEDIUM | 6.5 | 2.5% | Sep 13, 2022 | The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v... |
| CVE-2022-37190 | HIGH | 8.8 | 45.8% | Sep 13, 2022 | CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and... |
| CVE-2022-38633 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate pri... |
| CVE-2022-35582 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating sy... |
| CVE-2022-35413 | CRITICAL | 9.8 | 12.5% | Sep 13, 2022 | WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configur... |
| CVE-2022-34102 | HIGH | 8.8 | 0.9% | Sep 13, 2022 | Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39,... |
| CVE-2022-34101 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place... |
| CVE-2022-31861 | MEDIUM | 5.4 | 0.5% | Sep 13, 2022 | Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now