2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40877 | CRITICAL | 9.8 | 1.1% | Sep 27, 2022 | Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter. |
| CVE-2022-37346 | CRITICAL | 9.8 | 1.0% | Sep 27, 2022 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh... |
| CVE-2022-40050 | CRITICAL | 9.8 | 0.9% | Sep 26, 2022 | ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1. |
| CVE-2022-30004 | CRITICAL | 9.8 | 1.4% | Sep 26, 2022 | Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing ... |
| CVE-2022-3075 | CRITICAL | 9.6 | 5.7% | Sep 26, 2022 | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromi... |
| CVE-2022-28722 | CRITICAL | 9.8 | 1.0% | Sep 26, 2022 | Certain HP Print Products are potentially vulnerable to Buffer Overflow. |
| CVE-2022-28721 | CRITICAL | 9.8 | 1.5% | Sep 26, 2022 | Certain HP Print Products are potentially vulnerable to Remote Code Execution. |
| CVE-2022-40485 | CRITICAL | 9.8 | 1.0% | Sep 26, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php... |
| CVE-2022-40484 | CRITICAL | 9.8 | 1.0% | Sep 26, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_... |
| CVE-2022-40483 | CRITICAL | 9.8 | 1.0% | Sep 26, 2022 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.ph... |
| CVE-2022-39243 | CRITICAL | 9.8 | 1.1% | Sep 26, 2022 | NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks proc... |
| CVE-2022-21797 | CRITICAL | 9.8 | 1.9% | Sep 26, 2022 | The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Paral... |
| CVE-2022-41352 | CRITICAL | 9.8 | 95.5% | Sep 26, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama... |
| CVE-2022-23463 | CRITICAL | 9.8 | 1.7% | Sep 24, 2022 | Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. Discove... |
| CVE-2022-36025 | CRITICAL | 9.1 | 0.8% | Sep 24, 2022 | Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect... |
| CVE-2022-40122 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40121 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank... |
| CVE-2022-40120 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net... |
| CVE-2022-40119 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net... |
| CVE-2022-40118 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40117 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40116 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank... |
| CVE-2022-40115 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40114 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
| CVE-2022-40113 | CRITICAL | 9.8 | 0.8% | Sep 23, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now