2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30472 | CRITICAL | 9.8 | 1.3% | May 26, 2022 | Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat |
| CVE-2022-24422 | CRITICAL | 9.8 | 53.8% | May 26, 2022 | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A r... |
| CVE-2022-29660 | CRITICAL | 9.8 | 11.4% | May 26, 2022 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.ph... |
| CVE-2022-1664 | CRITICAL | 9.8 | 2.9% | May 26, 2022 | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is ... |
| CVE-2022-26833 | CRITICAL | 9.4 | 37.6% | May 25, 2022 | An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V... |
| CVE-2022-26082 | CRITICAL | 9.8 | 18.6% | May 25, 2022 | A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Pl... |
| CVE-2022-23775 | CRITICAL | 9.8 | 1.0% | May 25, 2022 | TrueStack Direct Connect 1.4.7 has Incorrect Access Control. |
| CVE-2022-29650 | CRITICAL | 9.8 | 1.2% | May 25, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /on... |
| CVE-2022-29379 | CRITICAL | 9.8 | 1.7% | May 25, 2022 | Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/nj... |
| CVE-2022-30595 | CRITICAL | 9.8 | 1.9% | May 25, 2022 | libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. |
| CVE-2022-28862 | CRITICAL | 9.8 | 1.0% | May 25, 2022 | In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWork... |
| CVE-2022-26945 | CRITICAL | 9.8 | 1.5% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of cus... |
| CVE-2022-29361 | CRITICAL | 9.8 | 7.7% | May 25, 2022 | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smugglin... |
| CVE-2022-29337 | CRITICAL | 9.8 | 35.3% | May 24, 2022 | C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter ... |
| CVE-2022-29334 | CRITICAL | 9.8 | 1.2% | May 24, 2022 | An issue in H v1.0 allows attackers to bypass authentication via a session replay attack. |
| CVE-2022-30838 | CRITICAL | 9.8 | 1.0% | May 24, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_applic... |
| CVE-2022-29246 | CRITICAL | 9.8 | 2.2% | May 24, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD f... |
| CVE-2022-29223 | CRITICAL | 9.8 | 1.1% | May 24, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can ... |
| CVE-2022-30461 | CRITICAL | 9.8 | 1.0% | May 24, 2022 | Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id |
| CVE-2022-30455 | CRITICAL | 9.8 | 1.0% | May 24, 2022 | Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental... |
| CVE-2022-30454 | CRITICAL | 9.8 | 1.0% | May 24, 2022 | Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product. |
| CVE-2022-1467 | CRITICAL | 9.9 | 0.9% | May 23, 2022 | Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enable... |
| CVE-2022-28932 | CRITICAL | 9.8 | 3.1% | May 23, 2022 | D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. |
| CVE-2022-29599 | CRITICAL | 9.8 | 4.0% | May 23, 2022 | In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without ... |
| CVE-2022-1014 | CRITICAL | 9.8 | 1.6% | May 23, 2022 | The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is b... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now