2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4995 | CRITICAL | 9.8 | — | Aug 7, 2026 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent... |
| CVE-2022-50973 | CRITICAL | 9.8 | — | Jul 2, 2026 | Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl... |
| CVE-2022-50972 | CRITICAL | 9.8 | 0.6% | Jun 20, 2026 | WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by ... |
| CVE-2022-50994 | CRITICAL | 9.2 | 1.4% | May 8, 2026 | DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han... |
| CVE-2022-50993 | CRITICAL | 9.8 | 0.8% | Apr 30, 2026 | Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability ... |
| CVE-2022-50981 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b... |
| CVE-2022-25369 | CRITICAL | 9.8 | 40.7% | Jan 23, 2026 | An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication... |
| CVE-2022-50935 | CRITICAL | 9.8 | 0.4% | Jan 13, 2026 | Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers ... |
| CVE-2022-50926 | CRITICAL | 9.8 | 0.5% | Jan 13, 2026 | WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipula... |
| CVE-2022-50925 | CRITICAL | 9.8 | 0.3% | Jan 13, 2026 | Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard... |
| CVE-2022-50922 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b... |
| CVE-2022-50919 | CRITICAL | 9.8 | 1.2% | Jan 13, 2026 | Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers... |
| CVE-2022-50912 | CRITICAL | 9.8 | 1.0% | Jan 13, 2026 | ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload p... |
| CVE-2022-50910 | CRITICAL | 9.8 | 0.7% | Jan 13, 2026 | Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows atta... |
| CVE-2022-50895 | CRITICAL | 9.8 | 0.6% | Jan 13, 2026 | Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate databa... |
| CVE-2022-50893 | CRITICAL | 9.8 | 0.8% | Jan 13, 2026 | VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functio... |
| CVE-2022-50892 | CRITICAL | 9.8 | 0.6% | Jan 13, 2026 | VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by ma... |
| CVE-2022-50803 | CRITICAL | 9.8 | 0.4% | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the dev... |
| CVE-2022-50796 | CRITICAL | 9.8 | 1.4% | Dec 30, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware uplo... |
| CVE-2022-50794 | CRITICAL | 9.8 | 3.3% | Dec 30, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the u... |
| CVE-2022-50696 | CRITICAL | 9.8 | 0.5% | Dec 30, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cann... |
| CVE-2022-50694 | CRITICAL | 9.8 | 0.8% | Dec 30, 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.ph... |
| CVE-2022-50691 | CRITICAL | 9.8 | 1.3% | Dec 30, 2025 | MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbi... |
| CVE-2022-50717 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds check on Transfer Tag ttag i... |
| CVE-2022-23851 | CRITICAL | 9.8 | 0.4% | Dec 17, 2025 | Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI). |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now