2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27077 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/upl... |
| CVE-2022-27076 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delA... |
| CVE-2022-26536 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setF... |
| CVE-2022-26290 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/Writ... |
| CVE-2022-26289 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeC... |
| CVE-2022-24934 | CRITICAL | 9.8 | 20.5% | Mar 23, 2022 | wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER i... |
| CVE-2022-23881 | CRITICAL | 9.8 | 56.5% | Mar 23, 2022 | ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_te... |
| CVE-2022-23880 | CRITICAL | 9.8 | 1.6% | Mar 23, 2022 | An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execu... |
| CVE-2022-25222 | CRITICAL | 9.8 | 1.6% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/... |
| CVE-2022-24293 | CRITICAL | 9.8 | 7.0% | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut... |
| CVE-2022-24292 | CRITICAL | 9.8 | 7.0% | Mar 23, 2022 | Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut... |
| CVE-2022-22952 | CRITICAL | 9.1 | 1.4% | Mar 23, 2022 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.... |
| CVE-2022-22951 | CRITICAL | 9.1 | 21.9% | Mar 23, 2022 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.... |
| CVE-2022-0888 | CRITICAL | 9.8 | 39.4% | Mar 23, 2022 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in... |
| CVE-2022-26189 | CRITICAL | 9.8 | 3.5% | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType para... |
| CVE-2022-26188 | CRITICAL | 9.8 | 3.5% | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncW... |
| CVE-2022-26187 | CRITICAL | 9.8 | 19.6% | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck fun... |
| CVE-2022-26186 | CRITICAL | 9.8 | 4.0% | Mar 22, 2022 | TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn in... |
| CVE-2022-26260 | CRITICAL | 9.8 | 1.3% | Mar 22, 2022 | Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse(). |
| CVE-2022-25517 | CRITICAL | 9.8 | 1.8% | Mar 22, 2022 | MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions... |
| CVE-2022-27228 | CRITICAL | 9.8 | 20.3% | Mar 22, 2022 | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can ex... |
| CVE-2022-26285 | CRITICAL | 9.8 | 2.0% | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the app... |
| CVE-2022-26284 | CRITICAL | 9.8 | 1.9% | Mar 21, 2022 | Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the... |
| CVE-2022-26283 | CRITICAL | 9.8 | 1.5% | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the vie... |
| CVE-2022-26184 | CRITICAL | 9.8 | 1.8% | Mar 21, 2022 | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in une... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now