2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1840MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Home Clean Services Management System 1.0. This ...
CVE-2022-1839HIGH8.8A vulnerability classified as critical was found in Home Clean Services Management System 1.0. This vulnerability affect...
CVE-2022-1838HIGH7.2A vulnerability classified as critical has been found in Home Clean Services Management System 1.0. This affects an unkn...
CVE-2022-1837HIGH7.2A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this ...
CVE-2022-1819MEDIUM4.8A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?pa...
CVE-2022-31263MEDIUM5.3app/models/user.rb in Mastodon before 3.5.0 allows a bypass of e-mail restrictions.
CVE-2022-29309HIGH7.5mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
CVE-2022-29305HIGH8.1imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.
CVE-2022-0910MEDIUM6.5A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/Zy...
CVE-2022-0734MEDIUM6.1A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35...
CVE-2022-29377HIGH7.5Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.c...
CVE-2022-30015MEDIUM5.4In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0...
CVE-2022-29376HIGH8.8Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing at...
CVE-2022-29002HIGH8.8A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via ...
CVE-2022-28999HIGH8.8Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary c...
CVE-2022-31489HIGH7.5Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.
CVE-2022-31488HIGH7.5Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.
CVE-2022-31487HIGH7.5Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/maste...
CVE-2022-1467CRITICAL9.9Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enable...
CVE-2022-31467HIGH7.3A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker ...
CVE-2022-31466HIGH7Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attack...
CVE-2022-28944HIGH8.8Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Pack...
CVE-2022-30017MEDIUM5.4Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.
CVE-2022-30016HIGH8.8Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=sy...
CVE-2022-30014HIGH8.8Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to tak...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now