2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38296 | CRITICAL | 9.8 | 3.7% | Sep 12, 2022 | Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager. |
| CVE-2022-38292 | CRITICAL | 9.8 | 0.8% | Sep 12, 2022 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the ... |
| CVE-2022-1700 | CRITICAL | 9.8 | 0.7% | Sep 12, 2022 | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss... |
| CVE-2022-37860 | CRITICAL | 9.8 | 80.0% | Sep 12, 2022 | The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication... |
| CVE-2022-37300 | CRITICAL | 9.8 | 0.7% | Sep 12, 2022 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized ac... |
| CVE-2022-37767 | CRITICAL | 9.8 | 1.1% | Sep 12, 2022 | Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with spr... |
| CVE-2022-37794 | CRITICAL | 9.8 | 0.9% | Sep 12, 2022 | In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. |
| CVE-2022-39135 | CRITICAL | 9.8 | 1.9% | Sep 11, 2022 | Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not rest... |
| CVE-2022-38638 | CRITICAL | 9.1 | 1.0% | Sep 9, 2022 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/u... |
| CVE-2022-36793 | CRITICAL | 9.1 | 0.7% | Sep 9, 2022 | Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress. |
| CVE-2022-36376 | CRITICAL | 9.8 | 0.7% | Sep 9, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress. |
| CVE-2022-2526 | CRITICAL | 9.8 | 1.1% | Sep 9, 2022 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream... |
| CVE-2022-40305 | CRITICAL | 9.8 | 1.2% | Sep 9, 2022 | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, ... |
| CVE-2022-25765 | CRITICAL | 9.8 | 38.9% | Sep 9, 2022 | The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. |
| CVE-2022-36098 | CRITICAL | 9 | 71.0% | Sep 8, 2022 | XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki p... |
| CVE-2022-36096 | CRITICAL | 9 | 59.5% | Sep 8, 2022 | The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki P... |
| CVE-2022-36094 | CRITICAL | 9 | 64.1% | Sep 8, 2022 | XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with vers... |
| CVE-2022-37164 | CRITICAL | 9.8 | 0.6% | Sep 8, 2022 | Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the ... |
| CVE-2022-37163 | CRITICAL | 9.8 | 0.5% | Sep 8, 2022 | Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized acce... |
| CVE-2022-36085 | CRITICAL | 9.8 | 1.2% | Sep 8, 2022 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit... |
| CVE-2022-20923 | CRITICAL | 9.8 | 0.8% | Sep 8, 2022 | A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and ... |
| CVE-2022-27593 | CRITICAL | 9.1 | 87.9% | Sep 8, 2022 | An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Statio... |
| CVE-2022-38394 | CRITICAL | 9.8 | 0.9% | Sep 8, 2022 | Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a... |
| CVE-2022-33941 | CRITICAL | 9.8 | 1.7% | Sep 8, 2022 | PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted me... |
| CVE-2022-25914 | CRITICAL | 9.8 | 1.3% | Sep 8, 2022 | The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDocker... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now