2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38278 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list. |
| CVE-2022-38277 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list. |
| CVE-2022-38276 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list. |
| CVE-2022-38275 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list. |
| CVE-2022-38274 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list. |
| CVE-2022-38273 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve. |
| CVE-2022-38272 | HIGH | 7.2 | 0.9% | Sep 9, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list. |
| CVE-2022-2528 | MEDIUM | 6.5 | 0.4% | Sep 9, 2022 | In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions... |
| CVE-2022-29061 | HIGH | 7.2 | 1.5% | Sep 9, 2022 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ... |
| CVE-2022-2925 | MEDIUM | 5.4 | 0.7% | Sep 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository appwrite/appwrite prior to 1.0.0-RC1. |
| CVE-2022-40307 | MEDIUM | 4.7 | 0.2% | Sep 9, 2022 | An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition w... |
| CVE-2022-40305 | CRITICAL | 9.8 | 1.2% | Sep 9, 2022 | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, ... |
| CVE-2022-25765 | CRITICAL | 9.8 | 38.9% | Sep 9, 2022 | The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. |
| CVE-2022-40299 | HIGH | 7.8 | 0.3% | Sep 9, 2022 | In Singular before 4.3.1, a predictable /tmp pathname is used (e.g., by sdb.cc), which allows local users to gain the pr... |
| CVE-2022-40297 | HIGH | 7.8 | 0.5% | Sep 9, 2022 | UBports Ubuntu Touch 16.04 allows the screen-unlock passcode to be used for a privileged shell via Sudo. This passcode i... |
| CVE-2022-40281 | HIGH | 7.5 | 0.5% | Sep 8, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has... |
| CVE-2022-40280 | HIGH | 7.5 | 1.0% | Sep 8, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio... |
| CVE-2022-36084 | HIGH | 8.8 | 1.1% | Sep 8, 2022 | cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl startin... |
| CVE-2022-38269 | HIGH | 7.2 | 0.7% | Sep 8, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo... |
| CVE-2022-38268 | HIGH | 7.2 | 0.7% | Sep 8, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo... |
| CVE-2022-38267 | HIGH | 7.2 | 0.7% | Sep 8, 2022 | School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the compo... |
| CVE-2022-38265 | HIGH | 7.2 | 0.7% | Sep 8, 2022 | Apartment Visitor Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete... |
| CVE-2022-36100 | HIGH | 8.8 | 73.6% | Sep 8, 2022 | XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Start... |
| CVE-2022-36099 | HIGH | 8.8 | 75.9% | Sep 8, 2022 | XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting ... |
| CVE-2022-36098 | CRITICAL | 9 | 71.0% | Sep 8, 2022 | XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now