2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29843 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running fir... |
| CVE-2022-25962 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input... |
| CVE-2022-25908 | CRITICAL | 9.8 | 1.5% | Jan 26, 2023 | All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to... |
| CVE-2022-25894 | CRITICAL | 9.8 | 2.6% | Jan 26, 2023 | All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionCont... |
| CVE-2022-25860 | CRITICAL | 9.8 | 2.7% | Jan 26, 2023 | Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), ... |
| CVE-2022-3806 | CRITICAL | 9.8 | 1.0% | Jan 25, 2023 | Inconsistent handling of error cases in bluetooth hci may lead to a double free condition of a network buffer. |
| CVE-2022-4693 | CRITICAL | 9.8 | 1.6% | Jan 23, 2023 | The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass au... |
| CVE-2022-4383 | CRITICAL | 9.8 | 1.0% | Jan 23, 2023 | The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in... |
| CVE-2022-4305 | CRITICAL | 9.8 | 38.6% | Jan 23, 2023 | The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to... |
| CVE-2022-0316 | CRITICAL | 9.8 | 2.1% | Jan 23, 2023 | The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme... |
| CVE-2022-48152 | CRITICAL | 9.8 | 0.8% | Jan 20, 2023 | SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive inform... |
| CVE-2022-48120 | CRITICAL | 9.8 | 0.9% | Jan 20, 2023 | SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9b... |
| CVE-2022-48126 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username para... |
| CVE-2022-48125 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password para... |
| CVE-2022-48124 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName para... |
| CVE-2022-48123 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername pa... |
| CVE-2022-48122 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid para... |
| CVE-2022-48121 | CRITICAL | 9.8 | 2.0% | Jan 20, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits param... |
| CVE-2022-40267 | CRITICAL | 9.1 | 1.2% | Jan 20, 2023 | Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F S... |
| CVE-2022-46476 | CRITICAL | 9.8 | 41.1% | Jan 19, 2023 | D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soap... |
| CVE-2022-46887 | CRITICAL | 9.8 | 19.4% | Jan 19, 2023 | Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL command... |
| CVE-2022-47740 | CRITICAL | 9.8 | 0.8% | Jan 19, 2023 | Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php. |
| CVE-2022-47105 | CRITICAL | 9.8 | 1.1% | Jan 19, 2023 | Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData. |
| CVE-2022-47966 | CRITICAL | 9.8 | 99.8% | Jan 18, 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due ... |
| CVE-2022-41417 | CRITICAL | 9.8 | 0.8% | Jan 18, 2023 | BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now