2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36714CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /sta...
CVE-2022-36713CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /lib...
CVE-2022-36712CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/st...
CVE-2022-36711CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bo...
CVE-2022-36709CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/ed...
CVE-2022-38625HIGH8.8Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware fil...
CVE-2022-37681HIGH7.5Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers ...
CVE-2022-37680HIGH7.5An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring syste...
CVE-2022-36560CRITICAL9.8Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers ...
CVE-2022-36559CRITICAL9.8Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping par...
CVE-2022-36558CRITICAL9.8Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able ...
CVE-2022-36557CRITICAL9.8Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the r...
CVE-2022-36556CRITICAL9.8Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddr...
CVE-2022-36555CRITICAL9.8Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked v...
CVE-2022-36554CRITICAL9.8A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 an...
CVE-2022-36553CRITICAL9.8Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w...
CVE-2022-38772HIGH8.8Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils...
CVE-2022-37177HIGH7.5HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by th...
CVE-2022-32993CRITICAL9.8TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
CVE-2022-21385MEDIUM6.2A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Bas...
CVE-2022-3035MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
CVE-2022-36037MEDIUM5.4kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal int...
CVE-2022-36036HIGH7.8mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection ...
CVE-2022-2638MEDIUM6.5The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which...
CVE-2022-2599MEDIUM6.1The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some par...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now