2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25080 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. ... |
| CVE-2022-25079 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25078 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" functi... |
| CVE-2022-25077 | CRITICAL | 9.8 | 32.6% | Feb 24, 2022 | TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" functi... |
| CVE-2022-25076 | CRITICAL | 9.8 | 3.2% | Feb 24, 2022 | TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" functio... |
| CVE-2022-25075 | CRITICAL | 9.8 | 56.2% | Feb 24, 2022 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function... |
| CVE-2022-25074 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr().... |
| CVE-2022-25073 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This v... |
| CVE-2022-25072 | CRITICAL | 9.8 | 13.0% | Feb 24, 2022 | TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fill... |
| CVE-2022-21142 | CRITICAL | 9.8 | 1.5% | Feb 24, 2022 | Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versio... |
| CVE-2022-25330 | CRITICAL | 9.8 | 4.9% | Feb 24, 2022 | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote atta... |
| CVE-2022-25329 | CRITICAL | 9.8 | 2.6% | Feb 24, 2022 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific ... |
| CVE-2022-0717 | CRITICAL | 9.1 | 0.9% | Feb 23, 2022 | Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2. |
| CVE-2022-21654 | CRITICAL | 9.8 | 1.1% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when s... |
| CVE-2022-23608 | CRITICAL | 9.8 | 4.0% | Feb 22, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-24553 | CRITICAL | 9.8 | 2.5% | Feb 21, 2022 | An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resul... |
| CVE-2022-0691 | CRITICAL | 9.8 | 2.2% | Feb 21, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. |
| CVE-2022-23848 | CRITICAL | 9.8 | 1.2% | Feb 20, 2022 | In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44... |
| CVE-2022-0686 | CRITICAL | 9.1 | 1.8% | Feb 20, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. |
| CVE-2022-25137 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3... |
| CVE-2022-25136 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4... |
| CVE-2022-25135 | CRITICAL | 9.8 | 3.0% | Feb 19, 2022 | A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3... |
| CVE-2022-25134 | CRITICAL | 9.8 | 3.0% | Feb 19, 2022 | A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5... |
| CVE-2022-25133 | CRITICAL | 9.8 | 2.9% | Feb 19, 2022 | A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4... |
| CVE-2022-25132 | CRITICAL | 9.8 | 2.9% | Feb 19, 2022 | A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now