2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-48353CRITICAL9.8Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege esc...
CVE-2022-48349CRITICAL9.1The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentia...
CVE-2022-48348CRITICAL9.1The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability ma...
CVE-2022-4126CRITICAL9.8Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and P...
CVE-2022-45597CRITICAL9.8ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability b...
CVE-2022-42499CRITICAL9.8In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. T...
CVE-2022-42498CRITICAL9.8In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to re...
CVE-2022-20532CRITICAL9.8In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. Thi...
CVE-2022-42948CRITICAL9.8Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted...
CVE-2022-28495CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebW...
CVE-2022-36413CRITICAL9.1Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset o...
CVE-2022-28496CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswor...
CVE-2022-28497CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_wri...
CVE-2022-28493CRITICAL9.8A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,
CVE-2022-28491CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost functio...
CVE-2022-28492CRITICAL9.8TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.
CVE-2022-22512CRITICAL9.8Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker...
CVE-2022-28494CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgr...
CVE-2022-45637CRITICAL9.8An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via ins...
CVE-2022-43663CRITICAL9.8An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.0...
CVE-2022-4933CRITICAL9.8A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice u...
CVE-2022-43605CRITICAL9.8An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack G...
CVE-2022-43604CRITICAL9.8An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack G...
CVE-2022-43441CRITICAL9.8A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A ...
CVE-2022-39216CRITICAL9.8Combodo iTop is an open source, web-based IT service management platform. Prior to versions 2.7.8 and 3.0.2-1, the reset...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now