2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-25131CRITICAL9.8A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmwar...
CVE-2022-25130CRITICAL9.8A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4....
CVE-2022-24049CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prio...
CVE-2022-24047CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01....
CVE-2022-0543CRITICAL10It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific...
CVE-2022-25337CRITICAL9.8Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image file...
CVE-2022-21215CRITICAL9.8This vulnerability could allow an attacker to force the server to create and execute a web request granting access to ba...
CVE-2022-21196CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21143CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21141CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-0671CRITICAL9.1A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large ...
CVE-2022-25322CRITICAL9.8ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
CVE-2022-0664CRITICAL9.8Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
CVE-2022-0631CRITICAL9.8Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-25315CRITICAL9.8In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-22922CRITICAL9.8TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable ...
CVE-2022-22916CRITICAL9.8O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
CVE-2022-22912CRITICAL9.8Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS...
CVE-2022-0623CRITICAL9.1Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-24984CRITICAL9.8Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated ...
CVE-2022-22885CRITICAL9.8Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
CVE-2022-22881CRITICAL9.8Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserCom...
CVE-2022-22880CRITICAL9.8Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/q...
CVE-2022-24086CRITICAL9.8Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v...
CVE-2022-23358CRITICAL9.8EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now