2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32519 | CRITICAL | 9.8 | 0.5% | Jan 30, 2023 | A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE ... |
| CVE-2022-32518 | CRITICAL | 9.8 | 0.5% | Jan 30, 2023 | A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE insta... |
| CVE-2022-32515 | CRITICAL | 9.8 | 0.6% | Jan 30, 2023 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force a... |
| CVE-2022-32514 | CRITICAL | 9.8 | 0.8% | Jan 30, 2023 | A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when ... |
| CVE-2022-32513 | CRITICAL | 9.8 | 0.7% | Jan 30, 2023 | A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device wh... |
| CVE-2022-22731 | CRITICAL | 9.8 | 0.8% | Jan 30, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a funct... |
| CVE-2022-0223 | CRITICAL | 9.8 | 0.8% | Jan 30, 2023 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could... |
| CVE-2022-48006 | CRITICAL | 9.8 | 0.9% | Jan 30, 2023 | An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP fil... |
| CVE-2022-4395 | CRITICAL | 9.8 | 17.6% | Jan 30, 2023 | The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthe... |
| CVE-2022-23334 | CRITICAL | 9.8 | 0.5% | Jan 30, 2023 | The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries... |
| CVE-2022-45788 | CRITICAL | 9.8 | 1.2% | Jan 30, 2023 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code exe... |
| CVE-2022-42484 | CRITICAL | 9.8 | 6.0% | Jan 30, 2023 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially... |
| CVE-2022-27596 | CRITICAL | 9.8 | 2.7% | Jan 30, 2023 | A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows ... |
| CVE-2022-43979 | CRITICAL | 9.8 | 0.8% | Jan 27, 2023 | There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that t... |
| CVE-2022-39811 | CRITICAL | 9.1 | 0.8% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGu... |
| CVE-2022-48108 | CRITICAL | 9.8 | 3.1% | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettin... |
| CVE-2022-48107 | CRITICAL | 9.8 | 3.1% | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettin... |
| CVE-2022-48011 | CRITICAL | 9.8 | 1.1% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerr... |
| CVE-2022-48008 | CRITICAL | 9.8 | 1.3% | Jan 27, 2023 | An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary... |
| CVE-2022-48066 | CRITICAL | 9.8 | 1.1% | Jan 27, 2023 | An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a craf... |
| CVE-2022-44298 | CRITICAL | 9.8 | 0.7% | Jan 27, 2023 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. |
| CVE-2022-46967 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admi... |
| CVE-2022-46966 | CRITICAL | 9.8 | 1.1% | Jan 26, 2023 | Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php. |
| CVE-2022-42493 | CRITICAL | 9.8 | 3.5% | Jan 26, 2023 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp... |
| CVE-2022-42492 | CRITICAL | 9.8 | 3.2% | Jan 26, 2023 | Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A sp... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now