2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25636HIGH7.8net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a ...
CVE-2022-25418CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
CVE-2022-25417CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
CVE-2022-25414CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
CVE-2022-25406CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR paramet...
CVE-2022-25405CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter...
CVE-2022-25404CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
CVE-2022-25403CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
CVE-2022-25402CRITICAL9.1An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
CVE-2022-25401HIGH7.5The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting ...
CVE-2022-25363MEDIUM6.5WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify pri...
CVE-2022-25360HIGH8.8WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload fil...
CVE-2022-25355MEDIUM5.3EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote...
CVE-2022-25293HIGH8.8A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t...
CVE-2022-25292HIGH8.8A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t...
CVE-2022-25291HIGH8.8An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-b...
CVE-2022-25290MEDIUM6.5WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve c...
CVE-2022-25104HIGH7.5HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/fi...
CVE-2022-25101HIGH7.8A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code vi...
CVE-2022-25099HIGH7.8A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via ...
CVE-2022-25098CRITICAL9.1ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
CVE-2022-25084CRITICAL9.8TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. Thi...
CVE-2022-25083CRITICAL9.8TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25082CRITICAL9.8TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab...
CVE-2022-25081CRITICAL9.8TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. Th...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now