2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24995 | CRITICAL | 9.8 | 13.6% | Mar 10, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability ... |
| CVE-2022-24652 | CRITICAL | 9.8 | 2.5% | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res... |
| CVE-2022-24651 | CRITICAL | 9.8 | 2.5% | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res... |
| CVE-2022-24609 | CRITICAL | 9.8 | 1.5% | Mar 10, 2022 | Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an a... |
| CVE-2022-24607 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. |
| CVE-2022-24606 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. |
| CVE-2022-24605 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. |
| CVE-2022-24604 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. |
| CVE-2022-24603 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. |
| CVE-2022-24602 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. |
| CVE-2022-24600 | CRITICAL | 9.8 | 1.3% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL ... |
| CVE-2022-24193 | CRITICAL | 9.8 | 6.0% | Mar 10, 2022 | CasaOS before v0.2.7 was discovered to contain a command injection vulnerability. |
| CVE-2022-23383 | CRITICAL | 9.1 | 1.5% | Mar 10, 2022 | YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page ca... |
| CVE-2022-22814 | CRITICAL | 9.8 | 2.3% | Mar 10, 2022 | The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation. |
| CVE-2022-22795 | CRITICAL | 9.1 | 1.0% | Mar 10, 2022 | Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can rea... |
| CVE-2022-0895 | CRITICAL | 9.8 | 1.7% | Mar 10, 2022 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-22806 | CRITICAL | 9.8 | 12.3% | Mar 9, 2022 | A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection t... |
| CVE-2022-22805 | CRITICAL | 9.8 | 11.7% | Mar 9, 2022 | A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause ... |
| CVE-2022-0715 | CRITICAL | 9.1 | 5.8% | Mar 9, 2022 | A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior ... |
| CVE-2022-0482 | CRITICAL | 9.1 | 38.1% | Mar 9, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments p... |
| CVE-2022-26314 | CRITICAL | 9.8 | 1.4% | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix ... |
| CVE-2022-26313 | CRITICAL | 9.8 | 0.9% | Mar 8, 2022 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In cert... |
| CVE-2022-0441 | CRITICAL | 9.8 | 85.3% | Mar 7, 2022 | The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account,... |
| CVE-2022-0434 | CRITICAL | 9.8 | 14.8% | Mar 7, 2022 | The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it i... |
| CVE-2022-0349 | CRITICAL | 9.8 | 34.4% | Mar 7, 2022 | The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now