2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36355 | MEDIUM | 5.4 | 0.4% | Sep 1, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <... |
| CVE-2022-28199 | MEDIUM | 6.5 | 1.8% | Sep 1, 2022 | NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where... |
| CVE-2022-37435 | HIGH | 8.8 | 1.1% | Sep 1, 2022 | Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi... |
| CVE-2022-38790 | MEDIUM | 5.4 | 0.6% | Sep 1, 2022 | Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a jav... |
| CVE-2022-36055 | MEDIUM | 6.5 | 0.8% | Sep 1, 2022 | Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b... |
| CVE-2022-36054 | HIGH | 8.8 | 0.6% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio... |
| CVE-2022-36053 | HIGH | 8.8 | 0.5% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 networ... |
| CVE-2022-36052 | HIGH | 8.8 | 0.5% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio... |
| CVE-2022-3072 | MEDIUM | 5.4 | 0.7% | Sep 1, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3. |
| CVE-2022-36676 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate... |
| CVE-2022-36675 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche... |
| CVE-2022-36674 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche... |
| CVE-2022-36672 | CRITICAL | 9.8 | 0.9% | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability ... |
| CVE-2022-36671 | HIGH | 7.5 | 0.4% | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download AP... |
| CVE-2022-36449 | MEDIUM | 6.5 | 0.9% | Sep 1, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2022-36130 | CRITICAL | 9.9 | 0.4% | Sep 1, 2022 | HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w... |
| CVE-2022-37130 | CRITICAL | 9.8 | 26.3% | Aug 31, 2022 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagn... |
| CVE-2022-37129 | HIGH | 8.8 | 8.3% | Aug 31, 2022 | D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in ... |
| CVE-2022-37123 | HIGH | 8.8 | 2.7% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi. |
| CVE-2022-36619 | HIGH | 7.5 | 1.0% | Aug 31, 2022 | In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC. |
| CVE-2022-36051 | HIGH | 8.8 | 0.8% | Aug 31, 2022 | ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the ... |
| CVE-2022-37125 | CRITICAL | 9.8 | 3.2% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. |
| CVE-2022-36620 | HIGH | 7.5 | 23.2% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting. |
| CVE-2022-36203 | MEDIUM | 6.1 | 0.7% | Aug 31, 2022 | Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads t... |
| CVE-2022-36202 | CRITICAL | 9.8 | 0.9% | Aug 31, 2022 | Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now