2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-29843CRITICAL9.8A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running fir...
CVE-2022-25962CRITICAL9.8All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input...
CVE-2022-25908CRITICAL9.8All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to...
CVE-2022-25894CRITICAL9.8All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionCont...
CVE-2022-25860CRITICAL9.8Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), ...
CVE-2022-3806CRITICAL9.8Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer.
CVE-2022-4693CRITICAL9.8The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass au...
CVE-2022-4383CRITICAL9.8The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in...
CVE-2022-4305CRITICAL9.8The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to...
CVE-2022-0316CRITICAL9.8The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme...
CVE-2022-48152CRITICAL9.8SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive inform...
CVE-2022-48120CRITICAL9.8SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9b...
CVE-2022-48126CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username para...
CVE-2022-48125CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password para...
CVE-2022-48124CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName para...
CVE-2022-48123CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername pa...
CVE-2022-48122CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid para...
CVE-2022-48121CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits param...
CVE-2022-40267CRITICAL9.1Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F S...
CVE-2022-46476CRITICAL9.8D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soap...
CVE-2022-46887CRITICAL9.8Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL command...
CVE-2022-47740CRITICAL9.8Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
CVE-2022-47105CRITICAL9.8Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-47966CRITICAL9.8Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due ...
CVE-2022-41417CRITICAL9.8BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now