2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-39852HIGH7.8A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release ...
CVE-2022-33896HIGH7.8A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based offi...
CVE-2022-3422HIGH7.5Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when ...
CVE-2022-41672HIGH8.1In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being...
CVE-2022-41355HIGH7.2Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /lea...
CVE-2022-27810HIGH7.5It was possible to trigger an infinite recursion condition in the error handler when Hermes executed specific maliciousl...
CVE-2022-41528HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter...
CVE-2022-41527HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser para...
CVE-2022-41526HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter i...
CVE-2022-41524HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, a...
CVE-2022-41523HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parame...
CVE-2022-42457HIGH7.2Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update...
CVE-2022-42250HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=...
CVE-2022-42249HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
CVE-2022-42243HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id...
CVE-2022-42242HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
CVE-2022-42241HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
CVE-2022-41556HIGH7.5A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exh...
CVE-2022-41521HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort pa...
CVE-2022-41520HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter...
CVE-2022-41517HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLangu...
CVE-2022-3389HIGH7.5Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
CVE-2022-39280HIGH7.5dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vul...
CVE-2022-39273HIGH7.5FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorizati...
CVE-2022-39265HIGH7.2MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now