2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39141HIGH7.8A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0...
CVE-2022-39140HIGH7.8A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0...
CVE-2022-39139HIGH7.8A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0...
CVE-2022-39138HIGH7.8A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0...
CVE-2022-39137HIGH7.8A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V34.0 (All versions < V34.0...
CVE-2022-38466HIGH7.8A vulnerability has been identified in CoreShield One-Way Gateway (OWG) Software (All versions < V2.2). The default inst...
CVE-2022-37302MEDIUM5.5A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause...
CVE-2022-37011CRITICAL9.8A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8...
CVE-2022-38304HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai...
CVE-2022-38303HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /emp...
CVE-2022-38302HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /mai...
CVE-2022-38297CRITICAL9.8UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
CVE-2022-38299MEDIUM4.3An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP int...
CVE-2022-38298HIGH8.8Appsmith v1.7.11 was discovered to allow attackers to execute an authenticated Server-Side Request Forgery (SSRF) via re...
CVE-2022-35572HIGH7.5On Linksys E5350 WiFi Router with firmware version 1.0.00.037 and lower, (and potentially other vendors/devices due to c...
CVE-2022-38610HIGH7.2Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed...
CVE-2022-38606HIGH7.2Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed...
CVE-2022-38605HIGH7.2Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi...
CVE-2022-38296CRITICAL9.8Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
CVE-2022-38295MEDIUM6.1Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. Thi...
CVE-2022-38292CRITICAL9.8SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the ...
CVE-2022-38291MEDIUM6.1SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via ...
CVE-2022-38135MEDIUM4.3Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with s...
CVE-2022-36174HIGH8.1FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulne...
CVE-2022-36173HIGH8.1FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the Fre...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now