2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-23740HIGH8.8CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterpri...
CVE-2022-44278HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
CVE-2022-44260HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the se...
CVE-2022-44259HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTim...
CVE-2022-44258HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTra...
CVE-2022-44257HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setO...
CVE-2022-44256HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLangua...
CVE-2022-44254HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg...
CVE-2022-44253HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosi...
CVE-2022-42896HIGH8.8There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_c...
CVE-2022-40770HIGH7.2Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can ...
CVE-2022-36337HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the Me...
CVE-2022-34830HIGH7.5An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GP...
CVE-2022-37772HIGH7.5Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose ...
CVE-2022-43751HIGH7.8McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the u...
CVE-2022-40870HIGH8.1The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnera...
CVE-2022-40303HIGH7.5An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE par...
CVE-2022-45331HIGH7.5AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnera...
CVE-2022-45330HIGH7.5AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This...
CVE-2022-41919HIGH8.8Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Ty...
CVE-2022-2791HIGH7.8Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File w...
CVE-2022-41943HIGH7.2sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver ...
CVE-2022-41942HIGH7.8Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the...
CVE-2022-41950HIGH7.8super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerabilit...
CVE-2022-39066HIGH8.8There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phon...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now