2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-32292CRITICAL9.8In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-ba...
CVE-2022-30285CRITICAL9.8In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This ...
CVE-2022-29807CRITICAL9.8A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow fo...
CVE-2022-35925CRITICAL9.8BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentic...
CVE-2022-35924CRITICAL9.1NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using ...
CVE-2022-35223CRITICAL9.8EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing ...
CVE-2022-34613CRITICAL9.8Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a...
CVE-2022-35422CRITICAL9.8Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.
CVE-2022-34956CRITICAL9.8Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_...
CVE-2022-34955CRITICAL9.8Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_...
CVE-2022-34954CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoicep...
CVE-2022-34953CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34952CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser...
CVE-2022-34951CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34950CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editprod...
CVE-2022-34949CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or passwo...
CVE-2022-34948CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbran...
CVE-2022-34947CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcate...
CVE-2022-34946CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-34945CRITICAL9.8Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g...
CVE-2022-31321CRITICAL9.1The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform ...
CVE-2022-31188CRITICAL9.8CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were foun...
CVE-2022-31183CRITICAL9.8fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on N...
CVE-2022-31181CRITICAL9.8PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to ...
CVE-2022-31180CRITICAL9.8Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now