2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24677 | CRITICAL | 9.8 | 2.3% | Feb 9, 2022 | Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration informatio... |
| CVE-2022-0139 | CRITICAL | 9.8 | 1.2% | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. |
| CVE-2022-23340 | CRITICAL | 9.8 | 1.5% | Feb 8, 2022 | Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results. |
| CVE-2022-21241 | CRITICAL | 9.6 | 3.1% | Feb 8, 2022 | Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrar... |
| CVE-2022-24552 | CRITICAL | 9.8 | 1.3% | Feb 6, 2022 | A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input ... |
| CVE-2022-22832 | CRITICAL | 9.8 | 14.1% | Feb 6, 2022 | An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u... |
| CVE-2022-22831 | CRITICAL | 9.8 | 11.4% | Feb 6, 2022 | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth... |
| CVE-2022-23614 | CRITICAL | 9.8 | 8.3% | Feb 4, 2022 | Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus... |
| CVE-2022-23611 | CRITICAL | 9.8 | 1.5% | Feb 4, 2022 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered... |
| CVE-2022-23609 | CRITICAL | 9.1 | 1.0% | Feb 4, 2022 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered... |
| CVE-2022-23587 | CRITICAL | 9.8 | 0.9% | Feb 4, 2022 | Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vu... |
| CVE-2022-23379 | CRITICAL | 9.8 | 1.4% | Feb 4, 2022 | Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid(). |
| CVE-2022-22987 | CRITICAL | 9.8 | 1.2% | Feb 4, 2022 | The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to ach... |
| CVE-2022-0365 | CRITICAL | 9.8 | 2.2% | Feb 4, 2022 | The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and e... |
| CVE-2022-23329 | CRITICAL | 9.8 | 14.4% | Feb 4, 2022 | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute ar... |
| CVE-2022-24260 | CRITICAL | 9.8 | 50.9% | Feb 4, 2022 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra... |
| CVE-2022-24259 | CRITICAL | 9.8 | 2.0% | Feb 4, 2022 | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalat... |
| CVE-2022-24171 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24170 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24168 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24167 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24165 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24150 | CRITICAL | 9.8 | 2.8% | Feb 4, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebM... |
| CVE-2022-24148 | CRITICAL | 9.8 | 2.8% | Feb 4, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This v... |
| CVE-2022-24144 | CRITICAL | 9.8 | 18.5% | Feb 4, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSettin... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now