2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2885MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-30036HIGH8.8MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product ...
CVE-2022-2921HIGH8.8Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0....
CVE-2022-38493HIGH7.5Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This all...
CVE-2022-2909HIGH8.8A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affe...
CVE-2022-36030CRITICAL9.8Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack ...
CVE-2022-35692MEDIUM5.3Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-35554MEDIUM6.1Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an at...
CVE-2022-2793HIGH7.8Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity...
CVE-2022-2792HIGH7.5Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and ...
CVE-2022-2790MEDIUM5.9Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryp...
CVE-2022-2789MEDIUM5.5Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of ...
CVE-2022-36233MEDIUM5.5Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.
CVE-2022-36171HIGH8.1MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
CVE-2022-36157HIGH8.8XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin...
CVE-2022-37175CRITICAL9.8Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
CVE-2022-36170HIGH8.8MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitra...
CVE-2022-36031MEDIUM6.5Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by...
CVE-2022-36009HIGH8.8gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alte...
CVE-2022-36008MEDIUM6.5Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC resul...
CVE-2022-2788HIGH7.3Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'...
CVE-2022-23460HIGH7.5Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lea...
CVE-2022-23459CRITICAL9.8Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value cla...
CVE-2022-22489CRITICAL9.1IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh...
CVE-2022-0542MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now