2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0985MEDIUM4.3Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without ha...
CVE-2022-28452CRITICAL9.8Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-24900HIGH8.6Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. V...
CVE-2022-1536MEDIUM5.4A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Das...
CVE-2022-1534HIGH7.1Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the progr...
CVE-2022-1533HIGH7.8Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary cod...
CVE-2022-1531CRITICAL9.8SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint...
CVE-2022-1530MEDIUM6.1Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute m...
CVE-2022-1526MEDIUM5.4A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST paramete...
CVE-2022-29907MEDIUM6.1The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise l...
CVE-2022-29906CRITICAL9.8The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf...
CVE-2022-29905MEDIUM4.3The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:Use...
CVE-2022-29904CRITICAL9.8The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQ...
CVE-2022-29903MEDIUM4.3The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF...
CVE-2022-24449CRITICAL9.8Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML doc...
CVE-2022-29556CRITICAL9.8The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub...
CVE-2022-29555HIGH8.8The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websoc...
CVE-2022-29081CRITICAL9.8Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnera...
CVE-2022-28477MEDIUM6.1WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-28454MEDIUM6.1Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-28060HIGH7.5SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.
CVE-2022-24898MEDIUM4.9org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 a...
CVE-2022-29413MEDIUM6.1Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 ...
CVE-2022-29412MEDIUM5.4Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers ...
CVE-2022-29411CRITICAL9.8SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQL...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now