2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-50902 | HIGH | 8.5 | 0.1% | Jan 13, 2026 | Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to pot... |
| CVE-2022-50901 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users ... |
| CVE-2022-50900 | HIGH | 7.8 | 0.2% | Jan 13, 2026 | Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary... |
| CVE-2022-50899 | HIGH | 8.7 | 0.5% | Jan 13, 2026 | Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re... |
| CVE-2022-50898 | HIGH | 8.8 | 1.1% | Jan 13, 2026 | NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa... |
| CVE-2022-50897 | HIGH | 8.7 | 0.5% | Jan 13, 2026 | mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulat... |
| CVE-2022-50896 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows atta... |
| CVE-2022-50895 | CRITICAL | 9.8 | 0.6% | Jan 13, 2026 | Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate databa... |
| CVE-2022-50894 | HIGH | 7.1 | 0.4% | Jan 13, 2026 | VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d... |
| CVE-2022-50893 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio... |
| CVE-2022-50892 | CRITICAL | 9.8 | 0.6% | Jan 13, 2026 | VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by ma... |
| CVE-2022-50891 | MEDIUM | 5.1 | 0.2% | Jan 13, 2026 | Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr... |
| CVE-2022-50890 | HIGH | 8.7 | 0.9% | Jan 13, 2026 | Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t... |
| CVE-2022-50808 | HIGH | 8.5 | 0.1% | Jan 13, 2026 | CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attacke... |
| CVE-2022-50807 | — | — | — | Jan 13, 2026 | Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. |
| CVE-2022-50806 | HIGH | 8.6 | 1.1% | Jan 13, 2026 | 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse... |
| CVE-2022-50805 | HIGH | 8.8 | 0.3% | Jan 13, 2026 | Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows atta... |
| CVE-2022-50693 | HIGH | 8.5 | 0.2% | Jan 13, 2026 | Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al... |
| CVE-2022-50804 | HIGH | 8.8 | 0.2% | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to pe... |
| CVE-2022-50803 | CRITICAL | 9.8 | 0.4% | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the dev... |
| CVE-2022-50802 | MEDIUM | 6.1 | 0.3% | Dec 30, 2025 | ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows una... |
| CVE-2022-50801 | MEDIUM | 5.1 | 0.2% | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing a... |
| CVE-2022-50800 | HIGH | 7.5 | 0.3% | Dec 30, 2025 | H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txt... |
| CVE-2022-50799 | HIGH | 7.5 | 0.4% | Dec 30, 2025 | Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption ... |
| CVE-2022-50798 | — | — | — | Dec 30, 2025 | Rejected reason: This candidate is a duplicate of CVE-2017-11359. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now