2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32207 | CRITICAL | 9.8 | 5.5% | Jul 7, 2022 | When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the ... |
| CVE-2022-25046 | CRITICAL | 9.8 | 45.3% | Jul 7, 2022 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted... |
| CVE-2022-33047 | CRITICAL | 9.8 | 1.2% | Jul 6, 2022 | OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c. |
| CVE-2022-31126 | CRITICAL | 9.8 | 41.0% | Jul 6, 2022 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R... |
| CVE-2022-31125 | CRITICAL | 9.8 | 15.9% | Jul 6, 2022 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R... |
| CVE-2022-34598 | CRITICAL | 9.8 | 5.3% | Jul 6, 2022 | The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary ... |
| CVE-2022-34597 | CRITICAL | 9.8 | 2.5% | Jul 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting. |
| CVE-2022-34596 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSett... |
| CVE-2022-34595 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status. |
| CVE-2022-21744 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code ex... |
| CVE-2022-20083 | CRITICAL | 9.8 | 2.2% | Jul 6, 2022 | In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code... |
| CVE-2022-33980 | CRITICAL | 9.8 | 34.8% | Jul 6, 2022 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expand... |
| CVE-2022-32386 | CRITICAL | 9.8 | 11.2% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan. |
| CVE-2022-32385 | CRITICAL | 9.8 | 2.4% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote). |
| CVE-2022-32383 | CRITICAL | 9.8 | 1.2% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function. |
| CVE-2022-32533 | CRITICAL | 9.8 | 3.2% | Jul 6, 2022 | Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including X... |
| CVE-2022-34972 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_v... |
| CVE-2022-32413 | CRITICAL | 9.8 | 1.5% | Jul 5, 2022 | An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file. |
| CVE-2022-32311 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-32310 | CRITICAL | 9.8 | 1.4% | Jul 5, 2022 | An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a cra... |
| CVE-2022-31856 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter ... |
| CVE-2022-2321 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This r... |
| CVE-2022-31836 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to c... |
| CVE-2022-34265 | CRITICAL | 9.8 | 73.3% | Jul 4, 2022 | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions a... |
| CVE-2022-33171 | CRITICAL | 9.8 | 20.3% | Jul 4, 2022 | The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now