2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34951CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34950CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editprod...
CVE-2022-34949CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or passwo...
CVE-2022-34948CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbran...
CVE-2022-34947CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcate...
CVE-2022-34946CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34945CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-37315HIGH7.5graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
CVE-2022-35922HIGH7.5Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connect...
CVE-2022-35921MEDIUM4.3fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu...
CVE-2022-35920HIGH7.5Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when ...
CVE-2022-35919LOW2.7MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions a...
CVE-2022-35918MEDIUM6.5Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custo...
CVE-2022-35917MEDIUM5.3Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized paymen...
CVE-2022-35916MEDIUM5.3OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for...
CVE-2022-35915MEDIUM5.3OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsIn...
CVE-2022-31198HIGH7.5OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor tha...
CVE-2022-31195HIGH7.2DSpace open source software is a repository application which provides durable access to digital resources. In affected ...
CVE-2022-31194HIGH7.2DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31193MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31192MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31191MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31189MEDIUM5.3DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-35118MEDIUM6.1PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2022-34530MEDIUM5.3An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames v...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now