2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36529HIGH8.8Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at...
CVE-2022-36522MEDIUM6.5Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools...
CVE-2022-35714MEDIUM5.4IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2022-34303MEDIUM6.7A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with...
CVE-2022-34302MEDIUM6.7A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or ...
CVE-2022-34301MEDIUM6.7A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass o...
CVE-2022-31773HIGH8.8IBM DataPower Gateway V10CD, 10.0.1, and 2018.4.1 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2022-0225MEDIUM5.4A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name whil...
CVE-2022-0217HIGH7.5It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML feat...
CVE-2022-0216MEDIUM4.4A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs whil...
CVE-2022-0207MEDIUM4.7A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values bei...
CVE-2022-0175MEDIUM5.5A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when...
CVE-2022-0171MEDIUM5.5A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-le...
CVE-2022-0168MEDIUM4.4A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c ...
CVE-2022-0084HIGH7.5A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a mess...
CVE-2022-25625HIGH8.8A malicious unauthorized PAM user can access the administration configuration data and change the values.
CVE-2022-36521HIGH7.5Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.
CVE-2022-37152CRITICAL9.8An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob"...
CVE-2022-37151HIGH7.5There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.
CVE-2022-37150MEDIUM5.4An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstnam...
CVE-2022-36683CRITICAL9.8Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas...
CVE-2022-36682CRITICAL9.8Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas...
CVE-2022-36681CRITICAL9.8Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas...
CVE-2022-36680CRITICAL9.8Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clas...
CVE-2022-36679CRITICAL9.8Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now