2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26869CRITICAL9.8Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated atta...
CVE-2022-26868HIGH7.8Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated ...
CVE-2022-26867HIGH8PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The data is taken as is, with...
CVE-2022-26866MEDIUM5.5Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged networ...
CVE-2022-22557HIGH7.8PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x ...
CVE-2022-22556HIGH7.5Dell PowerStore contains an Uncontrolled Resource Consumption Vulnerability in PowerStore User Interface. A remote unaut...
CVE-2022-31024MEDIUM6.5richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6....
CVE-2022-32019CRITICAL9.8Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax....
CVE-2022-31023HIGH7.5Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error mess...
CVE-2022-30429MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject...
CVE-2022-29704CRITICAL9.8BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.
CVE-2022-29597MEDIUM6.5Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated...
CVE-2022-26944MEDIUM6.5Percona XtraBackup 2.4.20 unintentionally writes the command line to any resulting backup file output. This may include ...
CVE-2022-26497MEDIUM5.4BigBlueButton Greenlight 2.11.1 allows XSS. A threat actor could have a username containing a JavaScript payload. The pa...
CVE-2022-25163CRITICAL9.8Improper Input Validation vulnerability in Mitsubishi Electric MELSEC-Q Series QJ71E71-100 first 5 digits of serial numb...
CVE-2022-1982MEDIUM6.5Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the ...
CVE-2022-1980MEDIUM4.8A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been rated as problematic. This issue aff...
CVE-2022-1979MEDIUM4.8A vulnerability was found in SourceCodester Product Show Room Site 1.0. It has been declared as problematic. This vulner...
CVE-2022-1716MEDIUM4.6Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's passw...
CVE-2022-31018HIGH7.5Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2...
CVE-2022-32028HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php...
CVE-2022-32027HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=...
CVE-2022-32026HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking....
CVE-2022-32025HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id...
CVE-2022-32024HIGH7.2Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now