2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1173 | MEDIUM | 5.4 | 1.5% | Apr 26, 2022 | stored xss in GitHub repository getgrav/grav prior to 1.7.33. |
| CVE-2022-27985 | CRITICAL | 9.8 | 6.9% | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php. |
| CVE-2022-27984 | CRITICAL | 9.8 | 6.9% | Apr 26, 2022 | CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/te... |
| CVE-2022-27469 | CRITICAL | 9.8 | 1.3% | Apr 26, 2022 | Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF). |
| CVE-2022-27468 | CRITICAL | 9.8 | 1.9% | Apr 26, 2022 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code vi... |
| CVE-2022-27299 | CRITICAL | 9.8 | 1.6% | Apr 26, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php. |
| CVE-2022-24706 | CRITICAL | 9.8 | 92.3% | Apr 26, 2022 | In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticati... |
| CVE-2022-29806 | CRITICAL | 9.8 | 66.3% | Apr 26, 2022 | ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an... |
| CVE-2022-29499 | CRITICAL | 9.8 | 55.4% | Apr 26, 2022 | The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorr... |
| CVE-2022-24880 | MEDIUM | 5.3 | 1.1% | Apr 25, 2022 | flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a serve... |
| CVE-2022-23457 | CRITICAL | 9.8 | 2.7% | Apr 25, 2022 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver... |
| CVE-2022-29419 | HIGH | 8.8 | 0.8% | Apr 25, 2022 | SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with... |
| CVE-2022-29418 | MEDIUM | 4.8 | 0.5% | Apr 25, 2022 | Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word... |
| CVE-2022-29417 | MEDIUM | 4.3 | 0.6% | Apr 25, 2022 | Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a... |
| CVE-2022-28290 | MEDIUM | 6.1 | 1.4% | Apr 25, 2022 | Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload execut... |
| CVE-2022-25866 | CRITICAL | 9.8 | 3.8% | Apr 25, 2022 | The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling ... |
| CVE-2022-1441 | HIGH | 7.8 | 0.9% | Apr 25, 2022 | MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to pars... |
| CVE-2022-0477 | MEDIUM | 4.9 | 0.9% | Apr 25, 2022 | An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting fr... |
| CVE-2022-27375 | MEDIUM | 6.5 | 0.4% | Apr 25, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at ... |
| CVE-2022-27374 | MEDIUM | 6.5 | 0.4% | Apr 25, 2022 | Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at ... |
| CVE-2022-26597 | MEDIUM | 6.1 | 0.7% | Apr 25, 2022 | Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7... |
| CVE-2022-26596 | MEDIUM | 6.1 | 0.7% | Apr 25, 2022 | Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7.... |
| CVE-2022-24792 | HIGH | 7.5 | 1.8% | Apr 25, 2022 | PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects... |
| CVE-2022-22392 | HIGH | 7.8 | 2.0% | Apr 25, 2022 | IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an... |
| CVE-2022-1396 | MEDIUM | 4.8 | 1.0% | Apr 25, 2022 | The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now