2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-34149CRITICAL9.8Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.
CVE-2022-2927CRITICAL9.8Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7.
CVE-2022-36198CRITICAL9.8Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin...
CVE-2022-34916CRITICAL9.8Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u...
CVE-2022-36030CRITICAL9.8Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack ...
CVE-2022-37175CRITICAL9.8Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet.
CVE-2022-23459CRITICAL9.8Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value cla...
CVE-2022-22489CRITICAL9.1IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh...
CVE-2022-36578CRITICAL9.8jizhicms v2.3.1 has SQL injection in the background.
CVE-2022-36606CRITICAL9.8Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database.
CVE-2022-36605CRITICAL9.8Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter.
CVE-2022-35201CRITICAL9.8Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.
CVE-2022-34615CRITICAL9.8Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t...
CVE-2022-36220CRITICAL9.8Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code e...
CVE-2022-29805CRITICAL9.8A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attacker...
CVE-2022-35540CRITICAL9.8Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain adminis...
CVE-2022-36947CRITICAL9.8Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.
CVE-2022-30601CRITICAL9.8Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated u...
CVE-2022-36729CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librar...
CVE-2022-36728CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staf...
CVE-2022-36727CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staf...
CVE-2022-36725CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /studen...
CVE-2022-36722CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /libra...
CVE-2022-25899CRITICAL9.8Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may...
CVE-2022-22730CRITICAL9.8Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthen...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now