2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-29321CRITICAL9.8D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan...
CVE-2022-28915CRITICAL9.8D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass par...
CVE-2022-28913CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet...
CVE-2022-28912CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet...
CVE-2022-28911CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet...
CVE-2022-28910CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename param...
CVE-2022-28909CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx param...
CVE-2022-28908CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin paramet...
CVE-2022-28907CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime functio...
CVE-2022-28906CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet...
CVE-2022-28905CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parame...
CVE-2022-28901CRITICAL9.8A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows a...
CVE-2022-28896CRITICAL9.8A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 all...
CVE-2022-28895CRITICAL9.8A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allo...
CVE-2022-29591CRITICAL9.8Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.
CVE-2022-28110CRITICAL9.8Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the l...
CVE-2022-24042CRITICAL9.1A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21....
CVE-2022-24039CRITICAL9A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02...
CVE-2022-30335CRITICAL9.8Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application w...
CVE-2022-28738CRITICAL9.8A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to ...
CVE-2022-27412CRITICAL9.8Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
CVE-2022-1013CRITICAL9.8The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be...
CVE-2022-0948CRITICAL9.8The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before us...
CVE-2022-0836CRITICAL9.8The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL...
CVE-2022-0826CRITICAL9.8The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL st...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now