2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-43755CRITICAL9.8A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to conti...
CVE-2022-31249CRITICAL9.8A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler o...
CVE-2022-3229CRITICAL9.8Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication...
CVE-2022-48311CRITICAL9**UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR...
CVE-2022-4681CRITICAL9.8The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL ...
CVE-2022-47071CRITICAL9.8In NVS365 V01, the background network test function can trigger command execution.
CVE-2022-48078CRITICAL9.8pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTre...
CVE-2022-31733CRITICAL9.1Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are acc...
CVE-2022-48021CRITICAL9.8A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message...
CVE-2022-38389CRITICAL9.1IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2022-22486CRITICAL9.1IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2022-48114CRITICAL9.8RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
CVE-2022-48113CRITICAL9.8A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet servic...
CVE-2022-48130CRITICAL9.8Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the para...
CVE-2022-48082CRITICAL9.8Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.as...
CVE-2022-48079CRITICAL9.8Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execu...
CVE-2022-47714CRITICAL9.8Last Yard 22.09.8-1 does not enforce HSTS headers
CVE-2022-47003CRITICAL9.8A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a...
CVE-2022-47002CRITICAL9.8A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio...
CVE-2022-45100CRITICAL9.8 Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unaut...
CVE-2022-45101CRITICAL9.8 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS....
CVE-2022-42971CRITICAL9.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution w...
CVE-2022-42970CRITICAL9.8A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionali...
CVE-2022-2329CRITICAL9.8A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to d...
CVE-2022-24324CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now