2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29567HIGH7.5The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communica...
CVE-2022-29246CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD f...
CVE-2022-29242HIGH7.5GOST engine is a reference implementation of the Russian GOST crypto algorithms for OpenSSL. TLS clients using GOST engi...
CVE-2022-29237MEDIUM5.4Opencast is a free and open source solution for automated video capture and distribution at scale. Prior to Opencast 10....
CVE-2022-29223CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can ...
CVE-2022-29221HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2022-29219HIGH7.5Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a pos...
CVE-2022-29217HIGH7.5PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an att...
CVE-2022-22306MEDIUM5.3An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 ...
CVE-2022-1850HIGH8.1Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.
CVE-2022-30837MEDIUM5.4Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipien...
CVE-2022-30464MEDIUM5.4ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Mas...
CVE-2022-30463HIGH8.8Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.
CVE-2022-30462MEDIUM5.4Water-billing-management-system v1.0 is affected by: Cross Site Scripting (XSS) via /wbms/classes/Users.php?f=save, firs...
CVE-2022-30461CRITICAL9.8Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id
CVE-2022-30460MEDIUM5.4Simple Social Networking Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /sns/classes/Users.php?f=save, firstn...
CVE-2022-30459HIGH8.8ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=del...
CVE-2022-30458MEDIUM5.4Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_p...
CVE-2022-30456MEDIUM5.4Badminton Center Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /bcms/classes/Master.php?f=save_c...
CVE-2022-30455CRITICAL9.8Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental...
CVE-2022-30454CRITICAL9.8Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.
CVE-2022-1848MEDIUM5.3Business Logic Errors in GitHub repository erudika/para prior to 1.45.11.
CVE-2022-26532HIGH7.8A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 t...
CVE-2022-26531HIGH7.8Multiple improper input validation flaws were identified in some CLI commands of Zyxel USG/ZyWALL series firmware versio...
CVE-2022-1840MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now