2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36355MEDIUM5.4Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <...
CVE-2022-28199MEDIUM6.5NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where...
CVE-2022-37435HIGH8.8Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi...
CVE-2022-38790MEDIUM5.4Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a jav...
CVE-2022-36055MEDIUM6.5Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b...
CVE-2022-36054HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio...
CVE-2022-36053HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 networ...
CVE-2022-36052HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio...
CVE-2022-3072MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3.
CVE-2022-36676HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate...
CVE-2022-36675HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche...
CVE-2022-36674HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche...
CVE-2022-36672CRITICAL9.8Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability ...
CVE-2022-36671HIGH7.5Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download AP...
CVE-2022-36449MEDIUM6.5An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2022-36130CRITICAL9.9HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w...
CVE-2022-37130CRITICAL9.8In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagn...
CVE-2022-37129HIGH8.8D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in ...
CVE-2022-37123HIGH8.8D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
CVE-2022-36619HIGH7.5In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
CVE-2022-36051HIGH8.8ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the ...
CVE-2022-37125CRITICAL9.8D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
CVE-2022-36620HIGH7.5D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
CVE-2022-36203MEDIUM6.1Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads t...
CVE-2022-36202CRITICAL9.8Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now