2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27332 | CRITICAL | 9.1 | 1.0% | Apr 27, 2022 | An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication.... |
| CVE-2022-27331 | MEDIUM | 4.3 | 0.7% | Apr 27, 2022 | An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active... |
| CVE-2022-27888 | MEDIUM | 5.5 | 0.2% | Apr 26, 2022 | Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive informati... |
| CVE-2022-26564 | MEDIUM | 6.1 | 2.7% | Apr 26, 2022 | HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 p... |
| CVE-2022-28918 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=... |
| CVE-2022-28528 | HIGH | 8.8 | 1.2% | Apr 26, 2022 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&p... |
| CVE-2022-28527 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/... |
| CVE-2022-28525 | HIGH | 8.8 | 0.9% | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_use... |
| CVE-2022-28524 | CRITICAL | 9.8 | 0.9% | Apr 26, 2022 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. |
| CVE-2022-28523 | HIGH | 8.1 | 1.0% | Apr 26, 2022 | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. |
| CVE-2022-28522 | MEDIUM | 5.4 | 0.6% | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=messag... |
| CVE-2022-28521 | CRITICAL | 9.8 | 1.5% | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. |
| CVE-2022-28450 | MEDIUM | 5.4 | 0.7% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new pos... |
| CVE-2022-28449 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upl... |
| CVE-2022-28059 | HIGH | 8.1 | 1.2% | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. |
| CVE-2022-28058 | HIGH | 8.1 | 1.2% | Apr 26, 2022 | Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php. |
| CVE-2022-28448 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code t... |
| CVE-2022-27854 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19... |
| CVE-2022-24866 | MEDIUM | 4.3 | 0.6% | Apr 26, 2022 | Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve... |
| CVE-2022-1466 | MEDIUM | 6.5 | 1.0% | Apr 26, 2022 | Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be ... |
| CVE-2022-28218 | MEDIUM | 5.5 | 0.2% | Apr 26, 2022 | An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (... |
| CVE-2022-24883 | CRITICAL | 9.8 | 2.2% | Apr 26, 2022 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authenticatio... |
| CVE-2022-24882 | HIGH | 7.5 | 2.7% | Apr 26, 2022 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM)... |
| CVE-2022-24881 | CRITICAL | 9.8 | 2.9% | Apr 26, 2022 | Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, a... |
| CVE-2022-23942 | HIGH | 7.5 | 3.1% | Apr 26, 2022 | Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lea... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now