2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-40943CRITICAL9.8Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.
CVE-2022-35156CRITICAL9.8Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /...
CVE-2022-40944CRITICAL9.8Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
CVE-2022-40315CRITICAL9.8A limited SQL injection risk was identified in the "browse list of users" site administration page.
CVE-2022-40314CRITICAL9.8A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
CVE-2022-2778CRITICAL9.8In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
CVE-2022-33880CRITICAL9.8hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the t...
CVE-2022-39266CRITICAL9.8isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, ...
CVE-2022-40887CRITICAL9.8SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-29503CRITICAL9.8A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1...
CVE-2022-40475CRITICAL9.8TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/download...
CVE-2022-40929CRITICAL9.8XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 ...
CVE-2022-40942CRITICAL9.8Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.
CVE-2022-40083CRITICAL9.6Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vul...
CVE-2022-28814CRITICAL9.8Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a ...
CVE-2022-28812CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-28811CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-22526CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows fo...
CVE-2022-22524CRITICAL9.4In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker...
CVE-2022-22522CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-30935CRITICAL9.1An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any...
CVE-2022-3332CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an...
CVE-2022-39033CRITICAL9.8Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c...
CVE-2022-41571CRITICAL9.8An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.
CVE-2022-41570CRITICAL9.8An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now