2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25636 | HIGH | 7.8 | 2.6% | Feb 24, 2022 | net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a ... |
| CVE-2022-25418 | CRITICAL | 9.8 | 1.7% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi. |
| CVE-2022-25417 | CRITICAL | 9.8 | 1.7% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo. |
| CVE-2022-25414 | CRITICAL | 9.8 | 10.4% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. |
| CVE-2022-25406 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR paramet... |
| CVE-2022-25405 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter... |
| CVE-2022-25404 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter. |
| CVE-2022-25403 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. |
| CVE-2022-25402 | CRITICAL | 9.1 | 1.6% | Feb 24, 2022 | An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files. |
| CVE-2022-25401 | HIGH | 7.5 | 2.2% | Feb 24, 2022 | The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting ... |
| CVE-2022-25363 | MEDIUM | 6.5 | 0.9% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify pri... |
| CVE-2022-25360 | HIGH | 8.8 | 1.3% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload fil... |
| CVE-2022-25355 | MEDIUM | 5.3 | 1.1% | Feb 24, 2022 | EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote... |
| CVE-2022-25293 | HIGH | 8.8 | 2.0% | Feb 24, 2022 | A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t... |
| CVE-2022-25292 | HIGH | 8.8 | 2.0% | Feb 24, 2022 | A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t... |
| CVE-2022-25291 | HIGH | 8.8 | 1.7% | Feb 24, 2022 | An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-b... |
| CVE-2022-25290 | MEDIUM | 6.5 | 0.7% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve c... |
| CVE-2022-25104 | HIGH | 7.5 | 1.1% | Feb 24, 2022 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/fi... |
| CVE-2022-25101 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code vi... |
| CVE-2022-25099 | HIGH | 7.8 | 1.1% | Feb 24, 2022 | A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via ... |
| CVE-2022-25098 | CRITICAL | 9.1 | 1.0% | Feb 24, 2022 | ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter. |
| CVE-2022-25084 | CRITICAL | 9.8 | 24.8% | Feb 24, 2022 | TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. Thi... |
| CVE-2022-25083 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25082 | CRITICAL | 9.8 | 16.1% | Feb 24, 2022 | TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab... |
| CVE-2022-25081 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. Th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now