2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37254 | MEDIUM | 5.4 | 0.4% | Aug 19, 2022 | DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configura... |
| CVE-2022-36579 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-36578 | CRITICAL | 9.8 | 0.8% | Aug 19, 2022 | jizhicms v2.3.1 has SQL injection in the background. |
| CVE-2022-36577 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. |
| CVE-2022-36225 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management functio... |
| CVE-2022-36224 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-36606 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. |
| CVE-2022-36605 | CRITICAL | 9.8 | 0.7% | Aug 19, 2022 | Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. |
| CVE-2022-36263 | HIGH | 7.3 | 0.4% | Aug 19, 2022 | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute ar... |
| CVE-2022-35201 | CRITICAL | 9.8 | 1.8% | Aug 19, 2022 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. |
| CVE-2022-34624 | MEDIUM | 5.9 | 0.7% | Aug 19, 2022 | Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi... |
| CVE-2022-34623 | — | — | — | Aug 19, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-32425. Reason: This candidate is a duplicate of ... |
| CVE-2022-34621 | MEDIUM | 6.5 | 0.7% | Aug 19, 2022 | Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attack... |
| CVE-2022-34615 | CRITICAL | 9.8 | 1.1% | Aug 19, 2022 | Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t... |
| CVE-2022-36220 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code e... |
| CVE-2022-35910 | MEDIUM | 5.4 | 0.7% | Aug 19, 2022 | In Jellyfin before 10.8, stored XSS allows theft of an admin access token. |
| CVE-2022-35909 | HIGH | 8.8 | 1.3% | Aug 19, 2022 | In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. |
| CVE-2022-2889 | HIGH | 7.8 | 0.5% | Aug 19, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0225. |
| CVE-2022-29805 | CRITICAL | 9.8 | 27.4% | Aug 19, 2022 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attacker... |
| CVE-2022-1021 | MEDIUM | 5.4 | 0.6% | Aug 19, 2022 | Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0. |
| CVE-2022-2886 | HIGH | 8.8 | 0.6% | Aug 19, 2022 | A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipu... |
| CVE-2022-2075 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build informati... |
| CVE-2022-2074 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Te... |
| CVE-2022-2049 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload functi... |
| CVE-2022-1901 | MEDIUM | 5.3 | 0.5% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now