2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-38296CRITICAL9.8Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
CVE-2022-38292CRITICAL9.8SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the ...
CVE-2022-1700CRITICAL9.8Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss...
CVE-2022-37860CRITICAL9.8The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication...
CVE-2022-37300CRITICAL9.8A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized ac...
CVE-2022-37767CRITICAL9.8Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with spr...
CVE-2022-37794CRITICAL9.8In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
CVE-2022-39135CRITICAL9.8Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not rest...
CVE-2022-38638CRITICAL9.1Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/u...
CVE-2022-36793CRITICAL9.1Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
CVE-2022-36376CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Rank Math SEO plugin <= 1.0.95 at WordPress.
CVE-2022-2526CRITICAL9.8A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream...
CVE-2022-40305CRITICAL9.8A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, ...
CVE-2022-25765CRITICAL9.8The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
CVE-2022-36098CRITICAL9XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki p...
CVE-2022-36096CRITICAL9The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki P...
CVE-2022-36094CRITICAL9XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with vers...
CVE-2022-37164CRITICAL9.8Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the ...
CVE-2022-37163CRITICAL9.8Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized acce...
CVE-2022-36085CRITICAL9.8Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit...
CVE-2022-20923CRITICAL9.8A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and ...
CVE-2022-27593CRITICAL9.1An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Statio...
CVE-2022-38394CRITICAL9.8Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a...
CVE-2022-33941CRITICAL9.8PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted me...
CVE-2022-25914CRITICAL9.8The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDocker...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now