2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29321 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan... |
| CVE-2022-28915 | CRITICAL | 9.8 | 6.5% | May 10, 2022 | D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass par... |
| CVE-2022-28913 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet... |
| CVE-2022-28912 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet... |
| CVE-2022-28911 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename paramet... |
| CVE-2022-28910 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename param... |
| CVE-2022-28909 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx param... |
| CVE-2022-28908 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin paramet... |
| CVE-2022-28907 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime functio... |
| CVE-2022-28906 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet... |
| CVE-2022-28905 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parame... |
| CVE-2022-28901 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows a... |
| CVE-2022-28896 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 all... |
| CVE-2022-28895 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allo... |
| CVE-2022-29591 | CRITICAL | 9.8 | 1.3% | May 10, 2022 | Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow. |
| CVE-2022-28110 | CRITICAL | 9.8 | 0.9% | May 10, 2022 | Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the l... |
| CVE-2022-24042 | CRITICAL | 9.1 | 0.9% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-24039 | CRITICAL | 9 | 1.8% | May 10, 2022 | A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02... |
| CVE-2022-30335 | CRITICAL | 9.8 | 1.1% | May 9, 2022 | Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application w... |
| CVE-2022-28738 | CRITICAL | 9.8 | 2.6% | May 9, 2022 | A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to ... |
| CVE-2022-27412 | CRITICAL | 9.8 | 3.7% | May 9, 2022 | Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request. |
| CVE-2022-1013 | CRITICAL | 9.8 | 6.6% | May 9, 2022 | The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is be... |
| CVE-2022-0948 | CRITICAL | 9.8 | 9.8% | May 9, 2022 | The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before us... |
| CVE-2022-0836 | CRITICAL | 9.8 | 1.7% | May 9, 2022 | The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL... |
| CVE-2022-0826 | CRITICAL | 9.8 | 9.0% | May 9, 2022 | The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL st... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now