2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1173MEDIUM5.4stored xss in GitHub repository getgrav/grav prior to 1.7.33.
CVE-2022-27985CRITICAL9.8CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
CVE-2022-27984CRITICAL9.8CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/te...
CVE-2022-27469CRITICAL9.8Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).
CVE-2022-27468CRITICAL9.8Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code vi...
CVE-2022-27299CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.
CVE-2022-24706CRITICAL9.8In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticati...
CVE-2022-29806CRITICAL9.8ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an...
CVE-2022-29499CRITICAL9.8The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorr...
CVE-2022-24880MEDIUM5.3flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a serve...
CVE-2022-23457CRITICAL9.8ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver...
CVE-2022-29419HIGH8.8SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with...
CVE-2022-29418MEDIUM4.8Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word...
CVE-2022-29417MEDIUM4.3Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an a...
CVE-2022-28290MEDIUM6.1Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload execut...
CVE-2022-25866CRITICAL9.8The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling ...
CVE-2022-1441HIGH7.8MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to pars...
CVE-2022-0477MEDIUM4.9An issue has been discovered in GitLab affecting all versions starting from 11.9 before 14.5.4, all versions starting fr...
CVE-2022-27375MEDIUM6.5Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_422168 at ...
CVE-2022-27374MEDIUM6.5Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via the function sub_42E328 at ...
CVE-2022-26597MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Layout module's Open Graph integration in Liferay Portal 7.3.0 through 7...
CVE-2022-26596MEDIUM6.1Cross-site scripting (XSS) vulnerability in Journal module's web content display configuration page in Liferay Portal 7....
CVE-2022-24792HIGH7.5PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects...
CVE-2022-22392HIGH7.8IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an...
CVE-2022-1396MEDIUM4.8The Donorbox WordPress plugin before 7.1.7 does not sanitise and escape its Campaign URL settings before outputting it i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now