2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25131 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmwar... |
| CVE-2022-25130 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.... |
| CVE-2022-24049 | CRITICAL | 9.8 | 6.8% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prio... |
| CVE-2022-24047 | CRITICAL | 9.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.... |
| CVE-2022-0543 | CRITICAL | 10 | 99.7% | Feb 18, 2022 | It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific... |
| CVE-2022-25337 | CRITICAL | 9.8 | 1.0% | Feb 18, 2022 | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image file... |
| CVE-2022-21215 | CRITICAL | 9.8 | 1.4% | Feb 18, 2022 | This vulnerability could allow an attacker to force the server to create and execute a web request granting access to ba... |
| CVE-2022-21196 | CRITICAL | 9.8 | 3.5% | Feb 18, 2022 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve... |
| CVE-2022-21143 | CRITICAL | 9.8 | 1.1% | Feb 18, 2022 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve... |
| CVE-2022-21141 | CRITICAL | 9.8 | 3.0% | Feb 18, 2022 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve... |
| CVE-2022-0671 | CRITICAL | 9.1 | 1.2% | Feb 18, 2022 | A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large ... |
| CVE-2022-25322 | CRITICAL | 9.8 | 8.6% | Feb 18, 2022 | ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. |
| CVE-2022-0664 | CRITICAL | 9.8 | 1.7% | Feb 18, 2022 | Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1. |
| CVE-2022-0631 | CRITICAL | 9.8 | 0.9% | Feb 18, 2022 | Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. |
| CVE-2022-25315 | CRITICAL | 9.8 | 4.8% | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
| CVE-2022-22922 | CRITICAL | 9.8 | 1.3% | Feb 18, 2022 | TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable ... |
| CVE-2022-22916 | CRITICAL | 9.8 | 39.9% | Feb 17, 2022 | O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. |
| CVE-2022-22912 | CRITICAL | 9.8 | 2.4% | Feb 17, 2022 | Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS... |
| CVE-2022-0623 | CRITICAL | 9.1 | 1.6% | Feb 17, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. |
| CVE-2022-24984 | CRITICAL | 9.8 | 2.5% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated ... |
| CVE-2022-22885 | CRITICAL | 9.8 | 1.3% | Feb 16, 2022 | Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation. |
| CVE-2022-22881 | CRITICAL | 9.8 | 1.4% | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserCom... |
| CVE-2022-22880 | CRITICAL | 9.8 | 1.4% | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/q... |
| CVE-2022-24086 | CRITICAL | 9.8 | 99.2% | Feb 16, 2022 | Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v... |
| CVE-2022-23358 | CRITICAL | 9.8 | 1.2% | Feb 16, 2022 | EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now