2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27461 | MEDIUM | 6.1 | 0.7% | May 4, 2022 | In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce... |
| CVE-2022-28508 | MEDIUM | 6.1 | 4.9% | May 4, 2022 | An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return param... |
| CVE-2022-28099 | HIGH | 8.8 | 1.6% | May 4, 2022 | Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /f... |
| CVE-2022-28090 | MEDIUM | 6.5 | 1.0% | May 4, 2022 | Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url... |
| CVE-2022-28082 | CRITICAL | 9.8 | 8.2% | May 4, 2022 | Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlLis... |
| CVE-2022-28081 | MEDIUM | 6.1 | 0.5% | May 4, 2022 | A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to exec... |
| CVE-2022-28076 | HIGH | 7.2 | 2.0% | May 4, 2022 | Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings. |
| CVE-2022-28067 | HIGH | 8.6 | 0.8% | May 4, 2022 | An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in t... |
| CVE-2022-28066 | — | — | — | May 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26280. Reason: This candidate is a duplicate of ... |
| CVE-2022-27903 | HIGH | 8.8 | 2.5% | May 4, 2022 | An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Com... |
| CVE-2022-25787 | MEDIUM | 6.7 | 0.2% | May 4, 2022 | Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system ... |
| CVE-2022-25785 | HIGH | 7.2 | 0.9% | May 4, 2022 | Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code executio... |
| CVE-2022-25784 | MEDIUM | 4.8 | 0.6% | May 4, 2022 | Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue... |
| CVE-2022-25783 | MEDIUM | 4.3 | 0.6% | May 4, 2022 | Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries ... |
| CVE-2022-25782 | MEDIUM | 5.4 | 0.5% | May 4, 2022 | Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to acc... |
| CVE-2022-25781 | MEDIUM | 6.1 | 0.5% | May 4, 2022 | Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript ... |
| CVE-2022-25780 | MEDIUM | 4.3 | 0.6% | May 4, 2022 | Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own s... |
| CVE-2022-25779 | MEDIUM | 4.3 | 0.5% | May 4, 2022 | Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries ... |
| CVE-2022-25778 | HIGH | 8.8 | 0.3% | May 4, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get r... |
| CVE-2022-28111 | CRITICAL | 9.8 | 1.6% | May 4, 2022 | MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulner... |
| CVE-2022-28096 | HIGH | 7.2 | 19.1% | May 4, 2022 | Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/De... |
| CVE-2022-1571 | MEDIUM | 6.1 | 0.8% | May 4, 2022 | Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. Th... |
| CVE-2022-1555 | MEDIUM | 6.1 | 1.2% | May 4, 2022 | DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, d... |
| CVE-2022-1502 | MEDIUM | 4.3 | 0.5% | May 4, 2022 | Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be ... |
| CVE-2022-28055 | CRITICAL | 9.8 | 1.5% | May 4, 2022 | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now