2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24821HIGH8.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users ca...
CVE-2022-1284MEDIUM5.5heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing den...
CVE-2022-27152MEDIUM5.7Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file m...
CVE-2022-1283MEDIUM5.5NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. Thi...
CVE-2022-27148MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.
CVE-2022-27147MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_...
CVE-2022-27146MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.
CVE-2022-27145MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_mo...
CVE-2022-27047CRITICAL9.8mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.
CVE-2022-22339HIGH7.3IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker...
CVE-2022-27046HIGH8.8libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
CVE-2022-27044HIGH8.8libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
CVE-2022-24229MEDIUM6.1A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers i...
CVE-2022-28002HIGH7.5Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page...
CVE-2022-28001CRITICAL9.8Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id ...
CVE-2022-28000HIGH8.8Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id par...
CVE-2022-27992HIGH8.8Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class...
CVE-2022-27991MEDIUM6.5Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via...
CVE-2022-27357CRITICAL9.8Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This v...
CVE-2022-27352HIGH8.8Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. Th...
CVE-2022-27351CRITICAL9.8Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacan...
CVE-2022-27349HIGH7.2Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerabil...
CVE-2022-27348MEDIUM4.8Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This v...
CVE-2022-27346HIGH8.8Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. Th...
CVE-2022-27064HIGH8.8Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerabi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now