2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27461MEDIUM6.1In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce...
CVE-2022-28508MEDIUM6.1An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return param...
CVE-2022-28099HIGH8.8Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /f...
CVE-2022-28090MEDIUM6.5Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url...
CVE-2022-28082CRITICAL9.8Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlLis...
CVE-2022-28081MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to exec...
CVE-2022-28076HIGH7.2Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.
CVE-2022-28067HIGH8.6An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in t...
CVE-2022-28066Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26280. Reason: This candidate is a duplicate of ...
CVE-2022-27903HIGH8.8An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Com...
CVE-2022-25787MEDIUM6.7Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system ...
CVE-2022-25785HIGH7.2Stack-based Buffer Overflow vulnerability in SiteManager allows logged-in or local user to cause arbitrary code executio...
CVE-2022-25784MEDIUM4.8Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue...
CVE-2022-25783MEDIUM4.3Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries ...
CVE-2022-25782MEDIUM5.4Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to acc...
CVE-2022-25781MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript ...
CVE-2022-25780MEDIUM4.3Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own s...
CVE-2022-25779MEDIUM4.3Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries ...
CVE-2022-25778HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Web UI of Secomea GateManager allows phishing attacker to issue get r...
CVE-2022-28111CRITICAL9.8MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulner...
CVE-2022-28096HIGH7.2Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/De...
CVE-2022-1571MEDIUM6.1Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. Th...
CVE-2022-1555MEDIUM6.1DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, d...
CVE-2022-1502MEDIUM4.3Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be ...
CVE-2022-28055CRITICAL9.8Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now