2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-32207CRITICAL9.8When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the ...
CVE-2022-25046CRITICAL9.8A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted...
CVE-2022-33047CRITICAL9.8OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
CVE-2022-31126CRITICAL9.8Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R...
CVE-2022-31125CRITICAL9.8Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R...
CVE-2022-34598CRITICAL9.8The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary ...
CVE-2022-34597CRITICAL9.8Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34596CRITICAL9.8Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSett...
CVE-2022-34595CRITICAL9.8Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
CVE-2022-21744CRITICAL9.8In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code ex...
CVE-2022-20083CRITICAL9.8In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code...
CVE-2022-33980CRITICAL9.8Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expand...
CVE-2022-32386CRITICAL9.8Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
CVE-2022-32385CRITICAL9.8Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
CVE-2022-32383CRITICAL9.8Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.
CVE-2022-32533CRITICAL9.8Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including X...
CVE-2022-34972CRITICAL9.8So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_v...
CVE-2022-32413CRITICAL9.8An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.
CVE-2022-32311CRITICAL9.8Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-32310CRITICAL9.8An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a cra...
CVE-2022-31856CRITICAL9.8Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter ...
CVE-2022-2321CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This r...
CVE-2022-31836CRITICAL9.8The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to c...
CVE-2022-34265CRITICAL9.8An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions a...
CVE-2022-33171CRITICAL9.8The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now