2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37254MEDIUM5.4DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configura...
CVE-2022-36579HIGH8.8Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36578CRITICAL9.8jizhicms v2.3.1 has SQL injection in the background.
CVE-2022-36577HIGH8.8An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
CVE-2022-36225HIGH8.8EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management functio...
CVE-2022-36224HIGH8.8XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36606CRITICAL9.8Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
CVE-2022-36605CRITICAL9.8Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
CVE-2022-36263HIGH7.3StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute ar...
CVE-2022-35201CRITICAL9.8Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
CVE-2022-34624MEDIUM5.9Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi...
CVE-2022-34623Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32425. Reason: This candidate is a duplicate of ...
CVE-2022-34621MEDIUM6.5Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attack...
CVE-2022-34615CRITICAL9.8Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t...
CVE-2022-36220CRITICAL9.8Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code e...
CVE-2022-35910MEDIUM5.4In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
CVE-2022-35909HIGH8.8In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.
CVE-2022-2889HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0225.
CVE-2022-29805CRITICAL9.8A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attacker...
CVE-2022-1021MEDIUM5.4Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
CVE-2022-2886HIGH8.8A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipu...
CVE-2022-2075HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build informati...
CVE-2022-2074HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Te...
CVE-2022-2049HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload functi...
CVE-2022-1901MEDIUM5.3In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now