2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20817HIGH7.4A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's...
CVE-2022-20798CRITICAL9.8A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Ci...
CVE-2022-20736MEDIUM5.3A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenti...
CVE-2022-20733CRITICAL9.8A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacke...
CVE-2022-20664HIGH7.7A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Managemen...
CVE-2022-32992HIGH7.2Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname pa...
CVE-2022-32991HIGH8.8Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.
CVE-2022-32302HIGH8.8Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ti...
CVE-2022-32301CRITICAL9.8YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Ho...
CVE-2022-32300HIGH8.8YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Actio...
CVE-2022-32299HIGH8.8YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/...
CVE-2022-32158CRITICAL10Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles ...
CVE-2022-32157HIGH7.5Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Reme...
CVE-2022-32156HIGH8.1In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not valida...
CVE-2022-32155HIGH7.5In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it...
CVE-2022-32154HIGH8.1Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token...
CVE-2022-32153HIGH8.1Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ...
CVE-2022-32152HIGH7.2Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ...
CVE-2022-32151CRITICAL9.1The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using t...
CVE-2022-32101CRITICAL9.8kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php...
CVE-2022-1342MEDIUM4.6A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensit...
CVE-2022-29453MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Googl...
CVE-2022-29442MEDIUM5.4Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress...
CVE-2022-29441MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows a...
CVE-2022-29440MEDIUM5.4Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now