2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34149 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress. |
| CVE-2022-2927 | CRITICAL | 9.8 | 0.8% | Aug 22, 2022 | Weak Password Requirements in GitHub repository notrinos/notrinoserp prior to 0.7. |
| CVE-2022-36198 | CRITICAL | 9.8 | 1.0% | Aug 22, 2022 | Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin... |
| CVE-2022-34916 | CRITICAL | 9.8 | 2.3% | Aug 21, 2022 | Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration u... |
| CVE-2022-36030 | CRITICAL | 9.8 | 0.7% | Aug 20, 2022 | Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack ... |
| CVE-2022-37175 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet. |
| CVE-2022-23459 | CRITICAL | 9.8 | 0.8% | Aug 19, 2022 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value cla... |
| CVE-2022-22489 | CRITICAL | 9.1 | 1.4% | Aug 19, 2022 | IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh... |
| CVE-2022-36578 | CRITICAL | 9.8 | 0.8% | Aug 19, 2022 | jizhicms v2.3.1 has SQL injection in the background. |
| CVE-2022-36606 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Ywoa before v6.1 was discovered to contain a SQL injection vulnerability via /oa/setup/checkPool?database. |
| CVE-2022-36605 | CRITICAL | 9.8 | 0.7% | Aug 19, 2022 | Yimioa v6.1 was discovered to contain a SQL injection vulnerability via the orderbyGET parameter. |
| CVE-2022-35201 | CRITICAL | 9.8 | 1.8% | Aug 19, 2022 | Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability. |
| CVE-2022-34615 | CRITICAL | 9.8 | 1.1% | Aug 19, 2022 | Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t... |
| CVE-2022-36220 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code e... |
| CVE-2022-29805 | CRITICAL | 9.8 | 27.4% | Aug 19, 2022 | A Java Deserialization vulnerability in the Fishbowl Server in Fishbowl Inventory before 2022.4.1 allows remote attacker... |
| CVE-2022-35540 | CRITICAL | 9.8 | 1.1% | Aug 18, 2022 | Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain adminis... |
| CVE-2022-36947 | CRITICAL | 9.8 | 2.0% | Aug 18, 2022 | Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow. |
| CVE-2022-30601 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated u... |
| CVE-2022-36729 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librar... |
| CVE-2022-36728 | CRITICAL | 9.8 | 0.9% | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staf... |
| CVE-2022-36727 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staf... |
| CVE-2022-36725 | CRITICAL | 9.8 | 0.9% | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /studen... |
| CVE-2022-36722 | CRITICAL | 9.8 | 0.9% | Aug 18, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /libra... |
| CVE-2022-25899 | CRITICAL | 9.8 | 1.0% | Aug 18, 2022 | Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may... |
| CVE-2022-22730 | CRITICAL | 9.8 | 0.8% | Aug 18, 2022 | Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthen... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now