2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25061 | CRITICAL | 9.8 | 72.5% | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_set... |
| CVE-2022-25060 | CRITICAL | 9.8 | 52.4% | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta... |
| CVE-2022-24442 | CRITICAL | 9.8 | 3.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
| CVE-2022-21798 | CRITICAL | 9.8 | 0.6% | Feb 25, 2022 | The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which ca... |
| CVE-2022-24340 | CRITICAL | 9.8 | 1.0% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. |
| CVE-2022-24331 | CRITICAL | 9.8 | 1.1% | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. |
| CVE-2022-25148 | CRITICAL | 9.8 | 81.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
| CVE-2022-25004 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame... |
| CVE-2022-25003 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame... |
| CVE-2022-22794 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userli... |
| CVE-2022-25809 | CRITICAL | 9.8 | 3.1% | Feb 24, 2022 | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice comma... |
| CVE-2022-25643 | CRITICAL | 9.8 | 2.1% | Feb 24, 2022 | seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The... |
| CVE-2022-25418 | CRITICAL | 9.8 | 1.7% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi. |
| CVE-2022-25417 | CRITICAL | 9.8 | 1.7% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo. |
| CVE-2022-25414 | CRITICAL | 9.8 | 10.4% | Feb 24, 2022 | Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR. |
| CVE-2022-25406 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR paramet... |
| CVE-2022-25405 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter... |
| CVE-2022-25404 | CRITICAL | 9.8 | 1.0% | Feb 24, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter. |
| CVE-2022-25403 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. |
| CVE-2022-25402 | CRITICAL | 9.1 | 1.6% | Feb 24, 2022 | An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files. |
| CVE-2022-25098 | CRITICAL | 9.1 | 1.0% | Feb 24, 2022 | ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter. |
| CVE-2022-25084 | CRITICAL | 9.8 | 24.8% | Feb 24, 2022 | TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. Thi... |
| CVE-2022-25083 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25082 | CRITICAL | 9.8 | 16.1% | Feb 24, 2022 | TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab... |
| CVE-2022-25081 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. Th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now