2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27367 | HIGH | 7.2 | 0.8% | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php... |
| CVE-2022-27366 | HIGH | 7.2 | 0.8% | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dan... |
| CVE-2022-27365 | HIGH | 7.2 | 0.9% | Apr 15, 2022 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php... |
| CVE-2022-27257 | HIGH | 7.5 | 1.2% | Apr 15, 2022 | A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote atta... |
| CVE-2022-27158 | CRITICAL | 9.8 | 1.2% | Apr 15, 2022 | pearweb < 1.32 suffers from Deserialization of Untrusted Data. |
| CVE-2022-27157 | CRITICAL | 9.8 | 1.1% | Apr 15, 2022 | pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php. |
| CVE-2022-27852 | MEDIUM | 6.1 | 0.7% | Apr 15, 2022 | Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 ver... |
| CVE-2022-27851 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API k... |
| CVE-2022-27850 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the cha... |
| CVE-2022-27849 | HIGH | 7.5 | 4.4% | Apr 15, 2022 | Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115 |
| CVE-2022-29268 | — | — | — | Apr 15, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-28109 | HIGH | 8.8 | 1.0% | Apr 15, 2022 | Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The i... |
| CVE-2022-27258 | MEDIUM | 6.1 | 0.7% | Apr 15, 2022 | Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla 7.0.3 and earlier allows remote attacker to include arbi... |
| CVE-2022-26594 | MEDIUM | 6.1 | 0.7% | Apr 15, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before se... |
| CVE-2022-23865 | CRITICAL | 9.8 | 1.5% | Apr 15, 2022 | Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vu... |
| CVE-2022-21159 | HIGH | 7.5 | 1.7% | Apr 15, 2022 | A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec6185... |
| CVE-2022-27043 | HIGH | 7.5 | 6.0% | Apr 15, 2022 | Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal. |
| CVE-2022-20761 | MEDIUM | 6.5 | 0.4% | Apr 15, 2022 | A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid R... |
| CVE-2022-20758 | MEDIUM | 6.8 | 1.1% | Apr 15, 2022 | A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IO... |
| CVE-2022-20747 | MEDIUM | 6.5 | 0.9% | Apr 15, 2022 | A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gai... |
| CVE-2022-20739 | HIGH | 7.3 | 0.6% | Apr 15, 2022 | A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbi... |
| CVE-2022-20735 | MEDIUM | 6.5 | 0.5% | Apr 15, 2022 | A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r... |
| CVE-2022-20731 | MEDIUM | 6.8 | 0.2% | Apr 15, 2022 | Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches c... |
| CVE-2022-20727 | MEDIUM | 6.7 | 1.0% | Apr 15, 2022 | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att... |
| CVE-2022-20726 | HIGH | 7.5 | 1.0% | Apr 15, 2022 | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now