A SQL injection vulnerability, tracked as CVE-2022-32025, affecting a car rental system has been added to the VulnCheck Known Exploited Vulnerabilities (KEV) catalog. The flaw was first publicly disclosed on June 2, 2022, but was not reported as exploited until September 14, 2026, approximately 1565 days after its initial publication.
The vulnerability's exploitation was identified through a public report collected from dashboard.shadowserver.org/statistics/honeypot/vulnerability on September 14, 2026. This report served as the basis for its inclusion in the VulnCheck KEV list.
While VulnCheck and CIRCL (an aggregator that mirrors VulnCheck's listings) have noted the exploitation, the vulnerability is not currently listed in the CISA KEV catalog for US federal agencies or the EUVD by ENISA for the European Union.
The CVE-2022-32025 record indicates a CVSS severity of "none" and an Exploit Prediction Scoring System (EPSS) percentile of 91.3%, suggesting a relatively high probability of exploitation despite the low CVSS score. The vulnerability was reserved on May 31, 2022, and published two days later.






