2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25865 | CRITICAL | 9.8 | 6.9% | May 13, 2022 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling t... |
| CVE-2022-25862 | HIGH | 7.5 | 0.7% | May 13, 2022 | This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.... |
| CVE-2022-22282 | CRITICAL | 9.8 | 7.2% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource u... |
| CVE-2022-22281 | HIGH | 7.8 | 0.5% | May 13, 2022 | A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earl... |
| CVE-2022-21190 | CRITICAL | 9.8 | 3.7% | May 13, 2022 | This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-J... |
| CVE-2022-1702 | MEDIUM | 6.1 | 8.4% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifie... |
| CVE-2022-1701 | HIGH | 7.5 | 4.4% | May 13, 2022 | SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key ... |
| CVE-2022-22393 | MEDIUM | 6.5 | 0.7% | May 13, 2022 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.5 , with the adminCenter-1.0 feature configured, could ... |
| CVE-2022-22325 | MEDIUM | 5.5 | 0.2% | May 13, 2022 | IBM MQ (IBM MQ for HPE NonStop 8.1.0) can inadvertently disclose sensitive information under certain circumstances to a ... |
| CVE-2022-1715 | CRITICAL | 9.8 | 1.3% | May 13, 2022 | Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07. |
| CVE-2022-29433 | MEDIUM | 5.4 | 0.5% | May 13, 2022 | Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPr... |
| CVE-2022-22252 | HIGH | 7.5 | 0.6% | May 13, 2022 | The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability. |
| CVE-2022-30417 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=. |
| CVE-2022-30415 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.p... |
| CVE-2022-30414 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_appl... |
| CVE-2022-30413 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_applic... |
| CVE-2022-30412 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.ph... |
| CVE-2022-30411 | HIGH | 7.2 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_indiv... |
| CVE-2022-30408 | MEDIUM | 6.5 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img. |
| CVE-2022-30407 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_... |
| CVE-2022-30404 | HIGH | 7.2 | 0.7% | May 13, 2022 | College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?t... |
| CVE-2022-30403 | HIGH | 7.2 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=. |
| CVE-2022-30402 | HIGH | 7.2 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_cate... |
| CVE-2022-30401 | HIGH | 7.2 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=. |
| CVE-2022-30400 | HIGH | 7.2 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now