2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35606 | CRITICAL | 9.8 | 0.7% | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ... |
| CVE-2022-35605 | CRITICAL | 9.8 | 0.7% | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi... |
| CVE-2022-35604 | — | — | — | Aug 18, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-35601. Reason: This candidate is a duplicate of ... |
| CVE-2022-35603 | CRITICAL | 9.8 | 0.7% | Aug 18, 2022 | A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ... |
| CVE-2022-35602 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi... |
| CVE-2022-35601 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ... |
| CVE-2022-35599 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit... |
| CVE-2022-35598 | CRITICAL | 9.8 | 0.7% | Aug 18, 2022 | A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to... |
| CVE-2022-35151 | MEDIUM | 6.1 | 1.2% | Aug 17, 2022 | kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and current... |
| CVE-2022-2869 | MEDIUM | 5.5 | 0.3% | Aug 17, 2022 | libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples... |
| CVE-2022-2868 | MEDIUM | 5.5 | 0.3% | Aug 17, 2022 | libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause... |
| CVE-2022-2867 | MEDIUM | 5.5 | 0.3% | Aug 17, 2022 | libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who suppl... |
| CVE-2022-28752 | HIGH | 7.8 | 0.1% | Aug 17, 2022 | Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulne... |
| CVE-2022-28751 | HIGH | 7.8 | 0.1% | Aug 17, 2022 | The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the... |
| CVE-2022-35148 | MEDIUM | 6.5 | 0.6% | Aug 17, 2022 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parame... |
| CVE-2022-35147 | CRITICAL | 9.8 | 1.3% | Aug 17, 2022 | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. |
| CVE-2022-35133 | MEDIUM | 6.1 | 0.4% | Aug 17, 2022 | A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or H... |
| CVE-2022-35122 | CRITICAL | 9.1 | 1.0% | Aug 17, 2022 | An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to a... |
| CVE-2022-2547 | HIGH | 7.5 | 1.3% | Aug 17, 2022 | A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integrati... |
| CVE-2022-2338 | MEDIUM | 5.3 | 0.2% | Aug 17, 2022 | Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The d... |
| CVE-2022-2337 | HIGH | 7.5 | 1.3% | Aug 17, 2022 | A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Ser... |
| CVE-2022-2336 | CRITICAL | 9.8 | 0.9% | Aug 17, 2022 | Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator crede... |
| CVE-2022-2335 | HIGH | 7.5 | 1.3% | Aug 17, 2022 | A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integra... |
| CVE-2022-2334 | HIGH | 7.2 | 9.5% | Aug 17, 2022 | The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the at... |
| CVE-2022-23765 | HIGH | 8.8 | 0.4% | Aug 17, 2022 | This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now