2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27332CRITICAL9.1An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication....
CVE-2022-27331MEDIUM4.3An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active...
CVE-2022-27888MEDIUM5.5Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive informati...
CVE-2022-26564MEDIUM6.1HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 p...
CVE-2022-28918HIGH8.1GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=...
CVE-2022-28528HIGH8.8bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&p...
CVE-2022-28527HIGH8.1dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/...
CVE-2022-28525HIGH8.8ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_use...
CVE-2022-28524CRITICAL9.8ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.
CVE-2022-28523HIGH8.1HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
CVE-2022-28522MEDIUM5.4ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=messag...
CVE-2022-28521CRITICAL9.8ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.
CVE-2022-28450MEDIUM5.4nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new pos...
CVE-2022-28449MEDIUM6.1nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upl...
CVE-2022-28059HIGH8.1Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
CVE-2022-28058HIGH8.1Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
CVE-2022-28448MEDIUM5.4nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code t...
CVE-2022-27854MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19...
CVE-2022-24866MEDIUM4.3Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve...
CVE-2022-1466MEDIUM6.5Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be ...
CVE-2022-28218MEDIUM5.5An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (...
CVE-2022-24883CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authenticatio...
CVE-2022-24882HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM)...
CVE-2022-24881CRITICAL9.8Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, a...
CVE-2022-23942HIGH7.5Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lea...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now