2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36714 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /sta... |
| CVE-2022-36713 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /lib... |
| CVE-2022-36712 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/st... |
| CVE-2022-36711 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bo... |
| CVE-2022-36709 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/ed... |
| CVE-2022-38625 | HIGH | 8.8 | 0.5% | Aug 29, 2022 | Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware fil... |
| CVE-2022-37681 | HIGH | 7.5 | 1.0% | Aug 29, 2022 | Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers ... |
| CVE-2022-37680 | HIGH | 7.5 | 0.7% | Aug 29, 2022 | An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring syste... |
| CVE-2022-36560 | CRITICAL | 9.8 | 0.7% | Aug 29, 2022 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers ... |
| CVE-2022-36559 | CRITICAL | 9.8 | 1.7% | Aug 29, 2022 | Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping par... |
| CVE-2022-36558 | CRITICAL | 9.8 | 0.7% | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able ... |
| CVE-2022-36557 | CRITICAL | 9.8 | 0.8% | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the r... |
| CVE-2022-36556 | CRITICAL | 9.8 | 1.5% | Aug 29, 2022 | Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddr... |
| CVE-2022-36555 | CRITICAL | 9.8 | 0.6% | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked v... |
| CVE-2022-36554 | CRITICAL | 9.8 | 2.2% | Aug 29, 2022 | A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 an... |
| CVE-2022-36553 | CRITICAL | 9.8 | 90.8% | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w... |
| CVE-2022-38772 | HIGH | 8.8 | 77.6% | Aug 29, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils... |
| CVE-2022-37177 | HIGH | 7.5 | 0.4% | Aug 29, 2022 | HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by th... |
| CVE-2022-32993 | CRITICAL | 9.8 | 0.8% | Aug 29, 2022 | TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh. |
| CVE-2022-21385 | MEDIUM | 6.2 | 0.3% | Aug 29, 2022 | A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Bas... |
| CVE-2022-3035 | MEDIUM | 4.8 | 0.6% | Aug 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11. |
| CVE-2022-36037 | MEDIUM | 5.4 | 0.7% | Aug 29, 2022 | kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal int... |
| CVE-2022-36036 | HIGH | 7.8 | 0.4% | Aug 29, 2022 | mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection ... |
| CVE-2022-2638 | MEDIUM | 6.5 | 0.9% | Aug 29, 2022 | The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which... |
| CVE-2022-2599 | MEDIUM | 6.1 | 1.0% | Aug 29, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some par... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now