2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-26255CRITICAL9.8Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxi...
CVE-2022-26245CRITICAL9.8Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/ho...
CVE-2022-1106CRITICAL9.1use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-26205CRITICAL9.8Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display tex...
CVE-2022-26198CRITICAL9.8Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected...
CVE-2022-22995CRITICAL9.8The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of file...
CVE-2022-22274CRITICAL9.8A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to ...
CVE-2022-24783CRITICAL10Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are ...
CVE-2022-27919CRITICAL9.8Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial conf...
CVE-2022-25577CRITICAL9.1ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user...
CVE-2022-1040CRITICAL9.8An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho...
CVE-2022-22687CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in ...
CVE-2022-26301CRITICAL9.8TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiCo...
CVE-2022-26279CRITICAL9.8EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
CVE-2022-26272CRITICAL9.8A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted ...
CVE-2022-26249CRITICAL9.8Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary cod...
CVE-2022-22374CRITICAL9.1The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affec...
CVE-2022-26629CRITICAL9.1An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due...
CVE-2022-27811CRITICAL9.8GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
CVE-2022-27083CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/upl...
CVE-2022-27082CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetI...
CVE-2022-27081CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetL...
CVE-2022-27080CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setW...
CVE-2022-27079CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setP...
CVE-2022-27078CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setA...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now