2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-0817CRITICAL9.8The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v...
CVE-2022-0814CRITICAL9.8The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters ...
CVE-2022-0592CRITICAL9.8The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it i...
CVE-2022-23066CRITICAL9.1In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementati...
CVE-2022-28470CRITICAL9.8marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
CVE-2022-29180CRITICAL9.8A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delet...
CVE-2022-29423CRITICAL9.8Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
CVE-2022-1053CRITICAL9.1Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and ...
CVE-2022-28163CRITICAL9.8In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL...
CVE-2022-28005CRITICAL9.8An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticate...
CVE-2022-29161CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypt...
CVE-2022-24817CRITICAL9.9Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, he...
CVE-2022-29535CRITICAL9.8Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
CVE-2022-27411CRITICAL9.8TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING par...
CVE-2022-27360CRITICAL9.8SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2022-28584CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu...
CVE-2022-28583CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2...
CVE-2022-28582CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28581CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7....
CVE-2022-28580CRITICAL9.8It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28579CRITICAL9.8It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28578CRITICAL9.8It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2...
CVE-2022-28577CRITICAL9.8It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28575CRITICAL9.8It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7...
CVE-2022-29592CRITICAL9.8Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now