2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27367HIGH7.2Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php...
CVE-2022-27366HIGH7.2Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dan...
CVE-2022-27365HIGH7.2Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php...
CVE-2022-27257HIGH7.5A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote atta...
CVE-2022-27158CRITICAL9.8pearweb < 1.32 suffers from Deserialization of Untrusted Data.
CVE-2022-27157CRITICAL9.8pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
CVE-2022-27852MEDIUM6.1Multiple Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabilities in KB Support (WordPress plugin) <= 1.5.5 ver...
CVE-2022-27851MEDIUM4.3Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API k...
CVE-2022-27850MEDIUM4.3Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the cha...
CVE-2022-27849HIGH7.5Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
CVE-2022-29268Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-28109HIGH8.8Selenium Selenium Grid (formerly Selenium Standalone Server) Fixed in 4.0.0-alpha-7 is affected by: DNS rebinding. The i...
CVE-2022-27258MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities in Hubzilla 7.0.3 and earlier allows remote attacker to include arbi...
CVE-2022-26594MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.5 through 7.4.0, and Liferay DXP 7.3 before se...
CVE-2022-23865CRITICAL9.8Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vu...
CVE-2022-21159HIGH7.5A denial of service vulnerability exists in the parseNormalModeParameters functionality of MZ Automation GmbH libiec6185...
CVE-2022-27043HIGH7.5Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.
CVE-2022-20761MEDIUM6.5A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid R...
CVE-2022-20758MEDIUM6.8A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IO...
CVE-2022-20747MEDIUM6.5A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gai...
CVE-2022-20739HIGH7.3A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbi...
CVE-2022-20735MEDIUM6.5A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, r...
CVE-2022-20731MEDIUM6.8Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches c...
CVE-2022-20727MEDIUM6.7Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att...
CVE-2022-20726HIGH7.5Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now