2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38278HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
CVE-2022-38277HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
CVE-2022-38276HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
CVE-2022-38275HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
CVE-2022-38274HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
CVE-2022-38273HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
CVE-2022-38272HIGH7.2JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
CVE-2022-2528MEDIUM6.5In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions...
CVE-2022-29061HIGH7.2An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2022-2925MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1.
CVE-2022-40307MEDIUM4.7An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition w...
CVE-2022-40305CRITICAL9.8A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, ...
CVE-2022-25765CRITICAL9.8The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
CVE-2022-40299HIGH7.8In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the pr...
CVE-2022-40297HIGH7.8UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode i...
CVE-2022-40281HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has...
CVE-2022-40280HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio...
CVE-2022-36084HIGH8.8cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl startin...
CVE-2022-38269HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38268HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38267HIGH7.2School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo...
CVE-2022-38265HIGH7.2Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete...
CVE-2022-36100HIGH8.8XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Start...
CVE-2022-36099HIGH8.8XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting ...
CVE-2022-36098CRITICAL9XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now