2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-4995CRITICAL9.8Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent...
CVE-2022-50973CRITICAL9.8Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl...
CVE-2022-50972CRITICAL9.8WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by ...
CVE-2022-50994CRITICAL9.2DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han...
CVE-2022-50993CRITICAL9.8Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability ...
CVE-2022-50981CRITICAL9.8An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b...
CVE-2022-25369CRITICAL9.8An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication...
CVE-2022-50935CRITICAL9.8Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers ...
CVE-2022-50926CRITICAL9.8WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipula...
CVE-2022-50925CRITICAL9.8Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard...
CVE-2022-50922CRITICAL9.8Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b...
CVE-2022-50919CRITICAL9.8Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers...
CVE-2022-50912CRITICAL9.8ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload p...
CVE-2022-50910CRITICAL9.8Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows atta...
CVE-2022-50895CRITICAL9.8Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate databa...
CVE-2022-50893CRITICAL9.8VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio...
CVE-2022-50892CRITICAL9.8VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by ma...
CVE-2022-50803CRITICAL9.8JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the dev...
CVE-2022-50796CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware uplo...
CVE-2022-50794CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the u...
CVE-2022-50696CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cann...
CVE-2022-50694CRITICAL9.8SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.ph...
CVE-2022-50691CRITICAL9.8MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbi...
CVE-2022-50717CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds check on Transfer Tag ttag i...
CVE-2022-23851CRITICAL9.8Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI).

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now