2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30514 | MEDIUM | 6.1 | 3.3% | Jun 2, 2022 | School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.p... |
| CVE-2022-30513 | MEDIUM | 6.1 | 3.3% | Jun 2, 2022 | School Dormitory Management System v1.0 is vulnerable to reflected cross-site scripting (XSS) via admin/inc/navigation.p... |
| CVE-2022-30512 | CRITICAL | 9.8 | 9.6% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. |
| CVE-2022-30511 | CRITICAL | 9.8 | 3.5% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. |
| CVE-2022-30510 | CRITICAL | 9.8 | 3.7% | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. |
| CVE-2022-30506 | CRITICAL | 9.8 | 2.5% | Jun 2, 2022 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code thro... |
| CVE-2022-30503 | MEDIUM | 5.5 | 0.3% | Jun 2, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h. |
| CVE-2022-30496 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user... |
| CVE-2022-30490 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | Badminton Center Management System V1.0 is vulnerable to SQL Injection via parameter 'id' in /bcms/admin/court_rentals/u... |
| CVE-2022-30482 | MEDIUM | 4.8 | 0.8% | Jun 2, 2022 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.p... |
| CVE-2022-30481 | CRITICAL | 9.8 | 1.5% | Jun 2, 2022 | Food-order-and-table-reservation-system- 1.0 is vulnerable to SQL Injection in categorywise-menu.php via the catid param... |
| CVE-2022-30478 | CRITICAL | 9.8 | 1.5% | Jun 2, 2022 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the key... |
| CVE-2022-30470 | CRITICAL | 9.8 | 2.5% | Jun 2, 2022 | In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file result... |
| CVE-2022-30425 | HIGH | 8.8 | 19.1% | Jun 2, 2022 | Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr a... |
| CVE-2022-30423 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | Merchandise Online Store v1.0 by oretnom23 has an arbitrary code execution (RCE) vulnerability in the user profile uploa... |
| CVE-2022-30352 | CRITICAL | 9.8 | 1.8% | Jun 2, 2022 | phpABook 0.9i is vulnerable to SQL Injection due to insufficient sanitization of user-supplied data in the "auth_user" p... |
| CVE-2022-30349 | MEDIUM | 6.1 | 0.6% | Jun 2, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-30324 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privi... |
| CVE-2022-30277 | MEDIUM | 5.7 | 0.2% | Jun 2, 2022 | BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited,... |
| CVE-2022-30115 | MEDIUM | 4.3 | 1.1% | Jun 2, 2022 | Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step ev... |
| CVE-2022-30034 | HIGH | 8.6 | 1.3% | Jun 2, 2022 | Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentica... |
| CVE-2022-29788 | MEDIUM | 6.5 | 0.8% | Jun 2, 2022 | libmobi before v0.10 contains a NULL pointer dereference via the component mobi_buffer_getpointer. This vulnerability al... |
| CVE-2022-29780 | MEDIUM | 5.5 | 0.4% | Jun 2, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_... |
| CVE-2022-29779 | MEDIUM | 5.5 | 0.4% | Jun 2, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_v... |
| CVE-2022-29777 | CRITICAL | 9.8 | 6.9% | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a heap overflow via t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now