2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40943 | CRITICAL | 9.8 | 1.0% | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file. |
| CVE-2022-35156 | CRITICAL | 9.8 | 1.3% | Sep 30, 2022 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /... |
| CVE-2022-40944 | CRITICAL | 9.8 | 1.1% | Sep 30, 2022 | Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file. |
| CVE-2022-40315 | CRITICAL | 9.8 | 0.8% | Sep 30, 2022 | A limited SQL injection risk was identified in the "browse list of users" site administration page. |
| CVE-2022-40314 | CRITICAL | 9.8 | 1.5% | Sep 30, 2022 | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. |
| CVE-2022-2778 | CRITICAL | 9.8 | 0.7% | Sep 30, 2022 | In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. |
| CVE-2022-33880 | CRITICAL | 9.8 | 0.7% | Sep 29, 2022 | hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the t... |
| CVE-2022-39266 | CRITICAL | 9.8 | 1.1% | Sep 29, 2022 | isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, ... |
| CVE-2022-40887 | CRITICAL | 9.8 | 0.9% | Sep 29, 2022 | SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection. |
| CVE-2022-29503 | CRITICAL | 9.8 | 1.2% | Sep 29, 2022 | A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1... |
| CVE-2022-40475 | CRITICAL | 9.8 | 3.5% | Sep 29, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/download... |
| CVE-2022-40929 | CRITICAL | 9.8 | 1.2% | Sep 28, 2022 | XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 ... |
| CVE-2022-40942 | CRITICAL | 9.8 | 8.1% | Sep 28, 2022 | Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time. |
| CVE-2022-40083 | CRITICAL | 9.6 | 2.3% | Sep 28, 2022 | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vul... |
| CVE-2022-28814 | CRITICAL | 9.8 | 1.1% | Sep 28, 2022 | Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a ... |
| CVE-2022-28812 | CRITICAL | 9.8 | 0.8% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker... |
| CVE-2022-28811 | CRITICAL | 9.8 | 1.0% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker... |
| CVE-2022-22526 | CRITICAL | 9.8 | 0.7% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows fo... |
| CVE-2022-22524 | CRITICAL | 9.4 | 0.9% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker... |
| CVE-2022-22522 | CRITICAL | 9.8 | 0.8% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker... |
| CVE-2022-30935 | CRITICAL | 9.1 | 1.0% | Sep 28, 2022 | An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any... |
| CVE-2022-3332 | CRITICAL | 9.8 | 0.6% | Sep 28, 2022 | A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an... |
| CVE-2022-39033 | CRITICAL | 9.8 | 1.5% | Sep 28, 2022 | Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c... |
| CVE-2022-41571 | CRITICAL | 9.8 | 0.8% | Sep 27, 2022 | An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur. |
| CVE-2022-41570 | CRITICAL | 9.8 | 0.7% | Sep 27, 2022 | An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now