2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-25061CRITICAL9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_set...
CVE-2022-25060CRITICAL9.8TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_sta...
CVE-2022-24442CRITICAL9.8JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2022-21798CRITICAL9.8The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which ca...
CVE-2022-24340CRITICAL9.8In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
CVE-2022-24331CRITICAL9.8In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
CVE-2022-25148CRITICAL9.8The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...
CVE-2022-25004CRITICAL9.8Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame...
CVE-2022-25003CRITICAL9.8Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame...
CVE-2022-22794CRITICAL9.8Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userli...
CVE-2022-25809CRITICAL9.8Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice comma...
CVE-2022-25643CRITICAL9.8seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The...
CVE-2022-25418CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
CVE-2022-25417CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.
CVE-2022-25414CRITICAL9.8Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.
CVE-2022-25406CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR paramet...
CVE-2022-25405CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter...
CVE-2022-25404CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.
CVE-2022-25403CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
CVE-2022-25402CRITICAL9.1An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
CVE-2022-25098CRITICAL9.1ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.
CVE-2022-25084CRITICAL9.8TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. Thi...
CVE-2022-25083CRITICAL9.8TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25082CRITICAL9.8TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerab...
CVE-2022-25081CRITICAL9.8TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. Th...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now