2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25080CRITICAL9.8TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. ...
CVE-2022-25079CRITICAL9.8TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25078CRITICAL9.8TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" functi...
CVE-2022-25077CRITICAL9.8TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" functi...
CVE-2022-25076CRITICAL9.8TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25075CRITICAL9.8TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function...
CVE-2022-25074CRITICAL9.8TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr()....
CVE-2022-25073CRITICAL9.8TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This v...
CVE-2022-25072CRITICAL9.8TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fill...
CVE-2022-24633MEDIUM5.3All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "p...
CVE-2022-24620MEDIUM5.4Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In thi...
CVE-2022-24615MEDIUM5.5zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result...
CVE-2022-24614MEDIUM5.5When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of mem...
CVE-2022-24613MEDIUM5.5metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which...
CVE-2022-24610HIGH8.6Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi ...
CVE-2022-24599MEDIUM6.5In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which...
CVE-2022-24582MEDIUM5.4Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is...
CVE-2022-24566MEDIUM5.4In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is...
CVE-2022-24565MEDIUM5.4Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XS...
CVE-2022-24435MEDIUM6.1Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an...
CVE-2022-24407HIGH8.8In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE...
CVE-2022-24374MEDIUM6.1Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version...
CVE-2022-23986HIGH7.5SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the i...
CVE-2022-23916MEDIUM6.1Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version...
CVE-2022-23810MEDIUM6.5Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms V...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now