2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-24995CRITICAL9.8Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability ...
CVE-2022-24652CRITICAL9.8sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res...
CVE-2022-24651CRITICAL9.8sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res...
CVE-2022-24609CRITICAL9.8Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an a...
CVE-2022-24607CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
CVE-2022-24606CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
CVE-2022-24605CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
CVE-2022-24604CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
CVE-2022-24603CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
CVE-2022-24602CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
CVE-2022-24600CRITICAL9.8Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL ...
CVE-2022-24193CRITICAL9.8CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
CVE-2022-23383CRITICAL9.1YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page ca...
CVE-2022-22814CRITICAL9.8The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
CVE-2022-22795CRITICAL9.1Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can rea...
CVE-2022-0895CRITICAL9.8Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-22806CRITICAL9.8A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection t...
CVE-2022-22805CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause ...
CVE-2022-0715CRITICAL9.1A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior ...
CVE-2022-0482CRITICAL9.1Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments p...
CVE-2022-26314CRITICAL9.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix ...
CVE-2022-26313CRITICAL9.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In cert...
CVE-2022-0441CRITICAL9.8The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,...
CVE-2022-0434CRITICAL9.8The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it i...
CVE-2022-0349CRITICAL9.8The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now