2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1815HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
CVE-2022-29405MEDIUM6.5In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
CVE-2022-29710MEDIUM6.1A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execu...
CVE-2022-29362MEDIUM5.4A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to exec...
CVE-2022-29361CRITICAL9.8Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smugglin...
CVE-2022-29359MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application ...
CVE-2022-29358MEDIUM5.5epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. Thi...
CVE-2022-29349MEDIUM6.1kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control...
CVE-2022-29337CRITICAL9.8C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter ...
CVE-2022-29334CRITICAL9.8An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.
CVE-2022-22497HIGH7.5IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-F...
CVE-2022-29333HIGH7.8A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.
CVE-2022-23050HIGH7.2ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hija...
CVE-2022-22977HIGH7.1VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious act...
CVE-2022-1669HIGH8.1A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The devi...
CVE-2022-22495HIGH8.8IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, w...
CVE-2022-22309MEDIUM6.8The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability ...
CVE-2022-29249HIGH7.5JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of loc...
CVE-2022-1849MEDIUM5.4Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
CVE-2022-31261HIGH7.5An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML iden...
CVE-2022-30843HIGH8.8Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.
CVE-2022-30842MEDIUM5.4Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=s...
CVE-2022-30839MEDIUM6.1Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, veh...
CVE-2022-30838CRITICAL9.8Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_applic...
CVE-2022-30457Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now