2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32292 | CRITICAL | 9.8 | 2.4% | Aug 3, 2022 | In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-ba... |
| CVE-2022-30285 | CRITICAL | 9.8 | 0.5% | Aug 2, 2022 | In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This ... |
| CVE-2022-29807 | CRITICAL | 9.8 | 1.1% | Aug 2, 2022 | A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow fo... |
| CVE-2022-35925 | CRITICAL | 9.8 | 1.4% | Aug 2, 2022 | BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentic... |
| CVE-2022-35924 | CRITICAL | 9.1 | 1.1% | Aug 2, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using ... |
| CVE-2022-35223 | CRITICAL | 9.8 | 1.3% | Aug 2, 2022 | EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing ... |
| CVE-2022-34613 | CRITICAL | 9.8 | 1.4% | Aug 2, 2022 | Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a... |
| CVE-2022-35422 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php. |
| CVE-2022-34956 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_... |
| CVE-2022-34955 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_... |
| CVE-2022-34954 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoicep... |
| CVE-2022-34953 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g... |
| CVE-2022-34952 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser... |
| CVE-2022-34951 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g... |
| CVE-2022-34950 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editprod... |
| CVE-2022-34949 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or passwo... |
| CVE-2022-34948 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbran... |
| CVE-2022-34947 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcate... |
| CVE-2022-34946 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g... |
| CVE-2022-34945 | CRITICAL | 9.8 | 0.8% | Aug 2, 2022 | Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at g... |
| CVE-2022-31321 | CRITICAL | 9.1 | 0.8% | Aug 1, 2022 | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform ... |
| CVE-2022-31188 | CRITICAL | 9.8 | 47.8% | Aug 1, 2022 | CVAT is an opensource interactive video and image annotation tool for computer vision. Versions prior to 2.0.0 were foun... |
| CVE-2022-31183 | CRITICAL | 9.8 | 0.6% | Aug 1, 2022 | fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on N... |
| CVE-2022-31181 | CRITICAL | 9.8 | 5.1% | Aug 1, 2022 | PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to ... |
| CVE-2022-31180 | CRITICAL | 9.8 | 1.5% | Aug 1, 2022 | Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now