2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35924CRITICAL9.1NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using ...
CVE-2022-30572MEDIUM6.5The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploi...
CVE-2022-30571MEDIUM5.4The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitab...
CVE-2022-2631HIGH8.8Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
CVE-2022-35223CRITICAL9.8EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing ...
CVE-2022-35222MEDIUM6.8HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter lengt...
CVE-2022-35221MEDIUM5.4Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread s...
CVE-2022-35220MEDIUM6.5Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A...
CVE-2022-35219MEDIUM5.5The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ...
CVE-2022-35218MEDIUM5.5The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p...
CVE-2022-35217HIGH7.8The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ...
CVE-2022-34625HIGH7.2Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to exe...
CVE-2022-23733MEDIUM5.4A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes...
CVE-2022-1293MEDIUM6.1The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.
CVE-2022-34618MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts...
CVE-2022-34613CRITICAL9.8Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a...
CVE-2022-29154HIGH7.4An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the d...
CVE-2022-25867HIGH7.5The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet wit...
CVE-2022-35422CRITICAL9.8Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
CVE-2022-35421HIGH7.2Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa...
CVE-2022-34956CRITICAL9.8Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_...
CVE-2022-34955CRITICAL9.8Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_...
CVE-2022-34954CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoicep...
CVE-2022-34953CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34952CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now