2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-46478CRITICAL9.8The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attacke...
CVE-2022-46471CRITICAL9.8Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter a...
CVE-2022-4616CRITICAL9.1The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis ...
CVE-2022-39185CRITICAL9.8EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user...
CVE-2022-39184CRITICAL9.8EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication...
CVE-2022-3515CRITICAL9.8A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can...
CVE-2022-4873CRITICAL9.8On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By p...
CVE-2022-4498CRITICAL9.8In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication...
CVE-2022-40615CRITICAL9.8 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could sen...
CVE-2022-47864CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
CVE-2022-47862CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
CVE-2022-47861CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
CVE-2022-47860CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
CVE-2022-47859CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVE-2022-47866CRITICAL9.8Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
CVE-2022-47865CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
CVE-2022-42967CRITICAL9.6Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This dire...
CVE-2022-34441CRITICAL9.8 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil...
CVE-2022-34440CRITICAL9.8Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabili...
CVE-2022-48253CRITICAL9.8nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands...
CVE-2022-48252CRITICAL9.8The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)...
CVE-2022-43389CRITICAL9.8A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, whic...
CVE-2022-4338CRITICAL9.8An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
CVE-2022-4337CRITICAL9.8An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
CVE-2022-4422CRITICAL9.8Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injectio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now