2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-45275HIGH7.2An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing Sy...
CVE-2022-42716HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp...
CVE-2022-41881HIGH7.5Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackO...
CVE-2022-3999HIGH8.1The DPD Baltic Shipping WordPress plugin before 1.2.57 does not have authorisation and CSRF in an AJAX action, which cou...
CVE-2022-3989HIGH8.8The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .ph...
CVE-2022-3981HIGH8.8The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a...
CVE-2022-3925HIGH7.2The buddybadges WordPress plugin through 1.0.0 does not sanitise and escape a parameter before using it in a SQL stateme...
CVE-2022-3912HIGH7.5The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX ac...
CVE-2022-3605HIGH7.8The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leadin...
CVE-2022-3359HIGH8.8The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported...
CVE-2022-45997HIGH7.2Tenda W20E V16.01.0.6(3392) is vulnerable to Buffer Overflow.
CVE-2022-45996HIGH7.2Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
CVE-2022-45980HIGH8.8Tenda AX12 V22.03.01.21_CN was discovered to contain a Cross-Site Request Forgery (CSRF) via /goform/SysToolRestoreSet .
CVE-2022-45979HIGH7.5Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the ssid parameter at /goform/fast_setting_wif...
CVE-2022-45977HIGH8.8Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
CVE-2022-45957HIGH7.5ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.
CVE-2022-45043HIGH8.8Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
CVE-2022-45968HIGH8.8Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (ev...
CVE-2022-44654HIGH7.5Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied wi...
CVE-2022-44653HIGH7.8A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local...
CVE-2022-44652HIGH7.8An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could all...
CVE-2022-44651HIGH7A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a loca...
CVE-2022-44650HIGH7.8A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as ...
CVE-2022-44649HIGH7.8An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One...
CVE-2022-44533HIGH7.2A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run ar...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now