2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-50902HIGH8.5Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to pot...
CVE-2022-50901HIGH7.8Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users ...
CVE-2022-50900HIGH7.8Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary...
CVE-2022-50899HIGH8.7Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re...
CVE-2022-50898HIGH8.8NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa...
CVE-2022-50897HIGH8.7mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulat...
CVE-2022-50896MEDIUM6.1Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows atta...
CVE-2022-50895CRITICAL9.8Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate databa...
CVE-2022-50894HIGH7.1VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d...
CVE-2022-50893CRITICAL9.8VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio...
CVE-2022-50892CRITICAL9.8VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by ma...
CVE-2022-50891MEDIUM5.1Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr...
CVE-2022-50890HIGH8.7Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t...
CVE-2022-50808HIGH8.5CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attacke...
CVE-2022-50807Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
CVE-2022-50806HIGH8.64images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse...
CVE-2022-50805HIGH8.8Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows atta...
CVE-2022-50693HIGH8.5Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al...
CVE-2022-50804HIGH8.8JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to pe...
CVE-2022-50803CRITICAL9.8JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the dev...
CVE-2022-50802MEDIUM6.1ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows una...
CVE-2022-50801MEDIUM5.1JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing a...
CVE-2022-50800HIGH7.5H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txt...
CVE-2022-50799HIGH7.5Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption ...
CVE-2022-50798Rejected reason: This candidate is a duplicate of CVE-2017-11359.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now