2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2892HIGH7.8Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-...
CVE-2022-36582HIGH7.2An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 a...
CVE-2022-36581HIGH7.5Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /a...
CVE-2022-36580HIGH7.2An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering Sys...
CVE-2022-36571HIGH7.2Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
CVE-2022-36570HIGH7.2Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
CVE-2022-36569HIGH8.8Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCf...
CVE-2022-36568HIGH8.8Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.
CVE-2022-34383HIGH8.2Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A loca...
CVE-2022-34373HIGH7.8Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability...
CVE-2022-31233HIGH8Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user...
CVE-2022-37184HIGH8.8The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authe...
CVE-2022-38152HIGH7.5An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is cal...
CVE-2022-3028HIGH7A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple ca...
CVE-2022-37122HIGH7.5Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 s...
CVE-2022-2866HIGH7.8FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a ...
CVE-2022-2759HIGH8.6Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions w...
CVE-2022-2590HIGH7A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of pr...
CVE-2022-2485HIGH7.5Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device resp...
CVE-2022-2132HIGH8.6A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of ser...
CVE-2022-2044HIGH8.2MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite ...
CVE-2022-2043HIGH7.5MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unre...
CVE-2022-2006HIGH7.8AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code...
CVE-2022-2005HIGH7.5AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server...
CVE-2022-2004HIGH7.5AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to preven...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now