2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0817 | CRITICAL | 9.8 | 11.5% | May 9, 2022 | The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement v... |
| CVE-2022-0814 | CRITICAL | 9.8 | 8.9% | May 9, 2022 | The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters ... |
| CVE-2022-0592 | CRITICAL | 9.8 | 8.8% | May 9, 2022 | The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it i... |
| CVE-2022-23066 | CRITICAL | 9.1 | 2.2% | May 9, 2022 | In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementati... |
| CVE-2022-28470 | CRITICAL | 9.8 | 2.0% | May 8, 2022 | marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor. |
| CVE-2022-29180 | CRITICAL | 9.8 | 0.7% | May 7, 2022 | A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delet... |
| CVE-2022-29423 | CRITICAL | 9.8 | 1.0% | May 6, 2022 | Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. |
| CVE-2022-1053 | CRITICAL | 9.1 | 1.3% | May 6, 2022 | Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and ... |
| CVE-2022-28163 | CRITICAL | 9.8 | 0.9% | May 6, 2022 | In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL... |
| CVE-2022-28005 | CRITICAL | 9.8 | 6.2% | May 6, 2022 | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticate... |
| CVE-2022-29161 | CRITICAL | 9.8 | 0.4% | May 6, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypt... |
| CVE-2022-24817 | CRITICAL | 9.9 | 1.0% | May 6, 2022 | Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, he... |
| CVE-2022-29535 | CRITICAL | 9.8 | 93.4% | May 5, 2022 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
| CVE-2022-27411 | CRITICAL | 9.8 | 2.4% | May 5, 2022 | TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING par... |
| CVE-2022-27360 | CRITICAL | 9.8 | 2.0% | May 5, 2022 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. |
| CVE-2022-28584 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu... |
| CVE-2022-28583 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2... |
| CVE-2022-28582 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28581 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.... |
| CVE-2022-28580 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28579 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28578 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2... |
| CVE-2022-28577 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28575 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7... |
| CVE-2022-29592 | CRITICAL | 9.8 | 19.3% | May 5, 2022 | Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now