2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34960 | CRITICAL | 9.8 | 1.1% | Aug 25, 2022 | The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links... |
| CVE-2022-32839 | CRITICAL | 9.8 | 3.0% | Aug 24, 2022 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, S... |
| CVE-2022-37181 | CRITICAL | 9.8 | 1.0% | Aug 24, 2022 | 72crm 9.0 has an Arbitrary file upload vulnerability. |
| CVE-2022-20122 | CRITICAL | 9.8 | 0.4% | Aug 24, 2022 | The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre... |
| CVE-2022-38078 | CRITICAL | 9.8 | 1.9% | Aug 24, 2022 | Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially craft... |
| CVE-2022-35115 | CRITICAL | 9.8 | 0.7% | Aug 23, 2022 | IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the sear... |
| CVE-2022-37113 | CRITICAL | 9.8 | 13.4% | Aug 23, 2022 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php |
| CVE-2022-37112 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php |
| CVE-2022-37111 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php |
| CVE-2022-35726 | CRITICAL | 9.8 | 0.6% | Aug 23, 2022 | Broken Authentication vulnerability in yotuwp Video Gallery plugin <= 1.3.4.5 at WordPress. |
| CVE-2022-37223 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. |
| CVE-2022-37199 | CRITICAL | 9.8 | 0.8% | Aug 23, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. |
| CVE-2022-36261 | CRITICAL | 9.1 | 1.0% | Aug 23, 2022 | An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server w... |
| CVE-2022-35733 | CRITICAL | 9.8 | 1.2% | Aug 23, 2022 | Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA100... |
| CVE-2022-34919 | CRITICAL | 9.8 | 1.4% | Aug 23, 2022 | The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authentic... |
| CVE-2022-38667 | CRITICAL | 9.8 | 2.1% | Aug 22, 2022 | HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelini... |
| CVE-2022-30547 | CRITICAL | 9.9 | 63.7% | Aug 22, 2022 | A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit... |
| CVE-2022-2842 | CRITICAL | 9.8 | 0.7% | Aug 22, 2022 | A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown p... |
| CVE-2022-28712 | CRITICAL | 9 | 2.4% | Aug 22, 2022 | A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master co... |
| CVE-2022-26842 | CRITICAL | 9.6 | 2.9% | Aug 22, 2022 | A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.... |
| CVE-2022-35583 | CRITICAL | 9.8 | 11.3% | Aug 22, 2022 | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by inje... |
| CVE-2022-35150 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-37134 | CRITICAL | 9.8 | 21.2% | Aug 22, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrn... |
| CVE-2022-34858 | CRITICAL | 9.8 | 1.3% | Aug 22, 2022 | Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress. |
| CVE-2022-34773 | CRITICAL | 9.8 | 0.5% | Aug 22, 2022 | Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can be POST-ed to add addre... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now