2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-24677CRITICAL9.8Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration informatio...
CVE-2022-0139CRITICAL9.8Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-23340CRITICAL9.8Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
CVE-2022-21241CRITICAL9.6Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrar...
CVE-2022-24552CRITICAL9.8A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input ...
CVE-2022-22832CRITICAL9.8An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u...
CVE-2022-22831CRITICAL9.8An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth...
CVE-2022-23614CRITICAL9.8Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus...
CVE-2022-23611CRITICAL9.8iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered...
CVE-2022-23609CRITICAL9.1iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered...
CVE-2022-23587CRITICAL9.8Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vu...
CVE-2022-23379CRITICAL9.8Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
CVE-2022-22987CRITICAL9.8The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to ach...
CVE-2022-0365CRITICAL9.8The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and e...
CVE-2022-23329CRITICAL9.8A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute ar...
CVE-2022-24260CRITICAL9.8A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra...
CVE-2022-24259CRITICAL9.8An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalat...
CVE-2022-24171CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24170CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24168CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24167CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24165CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24150CRITICAL9.8Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebM...
CVE-2022-24148CRITICAL9.8Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This v...
CVE-2022-24144CRITICAL9.8Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSettin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now