2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1681HIGH7.2Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can g...
CVE-2022-1044MEDIUM6.5Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
CVE-2022-30594HIGH7.8The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass int...
CVE-2022-30592CRITICAL9.8liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY.
CVE-2022-30557HIGH7.5Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mish...
CVE-2022-29855MEDIUM6.8Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mi...
CVE-2022-29596CRITICAL9.8MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the U...
CVE-2022-30451HIGH8.8An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.
CVE-2022-30450CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php
CVE-2022-30449CRITICAL9.8Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via...
CVE-2022-30448CRITICAL9.8Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in tr...
CVE-2022-30063CRITICAL9.8ftcms <=2.1 was discovered to be vulnerable to code execution attacks .
CVE-2022-30453CRITICAL9.8ShopWind <= 3.4.2 has a RCE vulnerability in Database.php
CVE-2022-30452HIGH7.2ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php
CVE-2022-30062MEDIUM6.5ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php
CVE-2022-30061MEDIUM6.5ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp.
CVE-2022-30060HIGH8.8ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Write via admin/controllers/tp.php
CVE-2022-30059MEDIUM6.5Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\...
CVE-2022-30058MEDIUM5.3Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backen...
CVE-2022-30057MEDIUM5.4Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.
CVE-2022-30048CRITICAL9.8Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter...
CVE-2022-30047CRITICAL9.8Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderB...
CVE-2022-30040HIGH7.5Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimec...
CVE-2022-29848MEDIUM6.5In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke ...
CVE-2022-29847HIGH7.5In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now