2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25080 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. ... |
| CVE-2022-25079 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25078 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" functi... |
| CVE-2022-25077 | CRITICAL | 9.8 | 32.6% | Feb 24, 2022 | TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" functi... |
| CVE-2022-25076 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25075 | CRITICAL | 9.8 | 56.2% | Feb 24, 2022 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function... |
| CVE-2022-25074 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr().... |
| CVE-2022-25073 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This v... |
| CVE-2022-25072 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fill... |
| CVE-2022-24633 | MEDIUM | 5.3 | 0.8% | Feb 24, 2022 | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "p... |
| CVE-2022-24620 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In thi... |
| CVE-2022-24615 | MEDIUM | 5.5 | 0.7% | Feb 24, 2022 | zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result... |
| CVE-2022-24614 | MEDIUM | 5.5 | 0.7% | Feb 24, 2022 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of mem... |
| CVE-2022-24613 | MEDIUM | 5.5 | 0.8% | Feb 24, 2022 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which... |
| CVE-2022-24610 | HIGH | 8.6 | 0.9% | Feb 24, 2022 | Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi ... |
| CVE-2022-24599 | MEDIUM | 6.5 | 1.7% | Feb 24, 2022 | In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which... |
| CVE-2022-24582 | MEDIUM | 5.4 | 0.5% | Feb 24, 2022 | Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is... |
| CVE-2022-24566 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is... |
| CVE-2022-24565 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XS... |
| CVE-2022-24435 | MEDIUM | 6.1 | 0.9% | Feb 24, 2022 | Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an... |
| CVE-2022-24407 | HIGH | 8.8 | 4.1% | Feb 24, 2022 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE... |
| CVE-2022-24374 | MEDIUM | 6.1 | 0.9% | Feb 24, 2022 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version... |
| CVE-2022-23986 | HIGH | 7.5 | 1.7% | Feb 24, 2022 | SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the i... |
| CVE-2022-23916 | MEDIUM | 6.1 | 0.8% | Feb 24, 2022 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version... |
| CVE-2022-23810 | MEDIUM | 6.5 | 1.1% | Feb 24, 2022 | Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms V... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now