2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-0547CRITICAL9.8OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than...
CVE-2022-24637CRITICAL9.8Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh...
CVE-2022-24595CRITICAL9.8Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Cont...
CVE-2022-27240CRITICAL9.8scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
CVE-2022-26501CRITICAL9.8Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
CVE-2022-25760CRITICAL9.8All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructo...
CVE-2022-25354CRITICAL9.8The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to ...
CVE-2022-25352CRITICAL9.8The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** Thi...
CVE-2022-0749CRITICAL9.8This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the...
CVE-2022-0748CRITICAL9.8The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe ...
CVE-2022-1000CRITICAL9.8Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
CVE-2022-24074CRITICAL9.8Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from t...
CVE-2022-22273CRITICAL9.8Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure R...
CVE-2022-26293CRITICAL9.8Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-23812CRITICAL9.8This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets user...
CVE-2022-25251CRITICAL9.8When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all...
CVE-2022-25247CRITICAL9.8Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain com...
CVE-2022-0982CRITICAL9.8The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereb...
CVE-2022-27005CRITICAL9.8Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ...
CVE-2022-27004CRITICAL9.8Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ...
CVE-2022-27003CRITICAL9.8Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ...
CVE-2022-27002CRITICAL9.8Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name...
CVE-2022-27001CRITICAL9.8Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname ...
CVE-2022-27000CRITICAL9.8Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via ...
CVE-2022-26999CRITICAL9.8Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now