2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-25080CRITICAL9.8TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. ...
CVE-2022-25079CRITICAL9.8TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25078CRITICAL9.8TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" functi...
CVE-2022-25077CRITICAL9.8TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" functi...
CVE-2022-25076CRITICAL9.8TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" functio...
CVE-2022-25075CRITICAL9.8TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function...
CVE-2022-25074CRITICAL9.8TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr()....
CVE-2022-25073CRITICAL9.8TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This v...
CVE-2022-25072CRITICAL9.8TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fill...
CVE-2022-21142CRITICAL9.8Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versio...
CVE-2022-25330CRITICAL9.8Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote atta...
CVE-2022-25329CRITICAL9.8Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific ...
CVE-2022-0717CRITICAL9.1Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-21654CRITICAL9.8Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when s...
CVE-2022-23608CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-24553CRITICAL9.8An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resul...
CVE-2022-0691CRITICAL9.8Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVE-2022-23848CRITICAL9.8In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44...
CVE-2022-0686CRITICAL9.1Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
CVE-2022-25137CRITICAL9.8A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3...
CVE-2022-25136CRITICAL9.8A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4...
CVE-2022-25135CRITICAL9.8A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3...
CVE-2022-25134CRITICAL9.8A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5...
CVE-2022-25133CRITICAL9.8A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4...
CVE-2022-25132CRITICAL9.8A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now