2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1840 | MEDIUM | 4.8 | 0.6% | May 24, 2022 | A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This ... |
| CVE-2022-1839 | HIGH | 8.8 | 0.8% | May 24, 2022 | A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affect... |
| CVE-2022-1838 | HIGH | 7.2 | 0.9% | May 24, 2022 | A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn... |
| CVE-2022-1837 | HIGH | 7.2 | 1.1% | May 24, 2022 | A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this ... |
| CVE-2022-1819 | MEDIUM | 4.8 | 0.6% | May 24, 2022 | A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?pa... |
| CVE-2022-31263 | MEDIUM | 5.3 | 0.8% | May 24, 2022 | app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions. |
| CVE-2022-29309 | HIGH | 7.5 | 0.9% | May 24, 2022 | mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. |
| CVE-2022-29305 | HIGH | 8.1 | 0.9% | May 24, 2022 | imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost. |
| CVE-2022-0910 | MEDIUM | 6.5 | 0.7% | May 24, 2022 | A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/Zy... |
| CVE-2022-0734 | MEDIUM | 6.1 | 8.4% | May 24, 2022 | A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35... |
| CVE-2022-29377 | HIGH | 7.5 | 1.0% | May 24, 2022 | Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.c... |
| CVE-2022-30015 | MEDIUM | 5.4 | 0.5% | May 23, 2022 | In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0... |
| CVE-2022-29376 | HIGH | 8.8 | 1.2% | May 23, 2022 | Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at... |
| CVE-2022-29002 | HIGH | 8.8 | 0.4% | May 23, 2022 | A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via ... |
| CVE-2022-28999 | HIGH | 8.8 | 1.1% | May 23, 2022 | Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary c... |
| CVE-2022-31489 | HIGH | 7.5 | 1.0% | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection. |
| CVE-2022-31488 | HIGH | 7.5 | 1.0% | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection. |
| CVE-2022-31487 | HIGH | 7.5 | 1.1% | May 23, 2022 | Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/maste... |
| CVE-2022-1467 | CRITICAL | 9.9 | 0.9% | May 23, 2022 | Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enable... |
| CVE-2022-31467 | HIGH | 7.3 | 0.3% | May 23, 2022 | A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker ... |
| CVE-2022-31466 | HIGH | 7 | 0.2% | May 23, 2022 | Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attack... |
| CVE-2022-28944 | HIGH | 8.8 | 1.7% | May 23, 2022 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Pack... |
| CVE-2022-30017 | MEDIUM | 5.4 | 0.5% | May 23, 2022 | Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing. |
| CVE-2022-30016 | HIGH | 8.8 | 0.9% | May 23, 2022 | Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=sy... |
| CVE-2022-30014 | HIGH | 8.8 | 0.6% | May 23, 2022 | Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to tak... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now