2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35924 | CRITICAL | 9.1 | 1.1% | Aug 2, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using ... |
| CVE-2022-30572 | MEDIUM | 6.5 | 1.0% | Aug 2, 2022 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploi... |
| CVE-2022-30571 | MEDIUM | 5.4 | 0.4% | Aug 2, 2022 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitab... |
| CVE-2022-2631 | HIGH | 8.8 | 0.9% | Aug 2, 2022 | Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0. |
| CVE-2022-35223 | CRITICAL | 9.8 | 1.3% | Aug 2, 2022 | EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing ... |
| CVE-2022-35222 | MEDIUM | 6.8 | 0.3% | Aug 2, 2022 | HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter lengt... |
| CVE-2022-35221 | MEDIUM | 5.4 | 0.7% | Aug 2, 2022 | Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread s... |
| CVE-2022-35220 | MEDIUM | 6.5 | 0.8% | Aug 2, 2022 | Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A... |
| CVE-2022-35219 | MEDIUM | 5.5 | 0.2% | Aug 2, 2022 | The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ... |
| CVE-2022-35218 | MEDIUM | 5.5 | 0.2% | Aug 2, 2022 | The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p... |
| CVE-2022-35217 | HIGH | 7.8 | 0.2% | Aug 2, 2022 | The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ... |
| CVE-2022-34625 | HIGH | 7.2 | 2.2% | Aug 2, 2022 | Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to exe... |
| CVE-2022-23733 | MEDIUM | 5.4 | 0.5% | Aug 2, 2022 | A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes... |
| CVE-2022-1293 | MEDIUM | 6.1 | 0.4% | Aug 2, 2022 | The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions. |
| CVE-2022-34618 | MEDIUM | 5.4 | 0.7% | Aug 2, 2022 | A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts... |
| CVE-2022-34613 | CRITICAL | 9.8 | 1.4% | Aug 2, 2022 | Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a... |
| CVE-2022-29154 | HIGH | 7.4 | 1.7% | Aug 2, 2022 | An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the d... |
| CVE-2022-25867 | HIGH | 7.5 | 1.3% | Aug 2, 2022 | The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet wit... |
| CVE-2022-35422 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php. |
| CVE-2022-35421 | HIGH | 7.2 | 0.8% | Aug 2, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa... |
| CVE-2022-34956 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_... |
| CVE-2022-34955 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_... |
| CVE-2022-34954 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoicep... |
| CVE-2022-34953 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g... |
| CVE-2022-34952 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now