2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-40877CRITICAL9.8Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
CVE-2022-37346CRITICAL9.8EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh...
CVE-2022-40050CRITICAL9.8ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
CVE-2022-30004CRITICAL9.8Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing ...
CVE-2022-3075CRITICAL9.6Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromi...
CVE-2022-28722CRITICAL9.8Certain HP Print Products are potentially vulnerable to Buffer Overflow.
CVE-2022-28721CRITICAL9.8Certain HP Print Products are potentially vulnerable to Remote Code Execution.
CVE-2022-40485CRITICAL9.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php...
CVE-2022-40484CRITICAL9.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_...
CVE-2022-40483CRITICAL9.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.ph...
CVE-2022-39243CRITICAL9.8NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks proc...
CVE-2022-21797CRITICAL9.8The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Paral...
CVE-2022-41352CRITICAL9.8An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through ama...
CVE-2022-23463CRITICAL9.8Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. Discove...
CVE-2022-36025CRITICAL9.1Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect...
CVE-2022-40122CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40121CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank...
CVE-2022-40120CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net...
CVE-2022-40119CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net...
CVE-2022-40118CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40117CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40116CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-bank...
CVE-2022-40115CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40114CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...
CVE-2022-40113CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-ban...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now