2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-3792CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye ...
CVE-2022-43514CRITICAL9.8A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All ...
CVE-2022-47790CRITICAL9.8Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=displa...
CVE-2022-43974CRITICAL9.8MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a...
CVE-2022-33265CRITICAL9.8Memory corruption due to information exposure in Powerline Communication Firmware while sending different MMEs from a si...
CVE-2022-25890CRITICAL9.8All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input s...
CVE-2022-0668CRITICAL9.8JFrog Artifactory prior to 7.37.13 is vulnerable to Authentication Bypass, which can lead to Privilege Escalation when a...
CVE-2022-2666CRITICAL9.8A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability a...
CVE-2022-1101CRITICAL9.8A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issu...
CVE-2022-4880CRITICAL9.8A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankIn...
CVE-2022-39073CRITICAL9.8There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att...
CVE-2022-25923CRITICAL9.8Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali...
CVE-2022-44877CRITICAL9.8login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut...
CVE-2022-3929CRITICAL9.8 Communication between the client and the server application of the affected products is partially done using CORBA (Com...
CVE-2022-3927CRITICAL9.8 The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) fi...
CVE-2022-47544CRITICAL9.8An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.
CVE-2022-45995CRITICAL9.8There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the...
CVE-2022-47523CRITICAL9.8Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnera...
CVE-2022-22338CRITICAL9.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to SQL injection. A remote attacker c...
CVE-2022-45875CRITICAL9.8Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulne...
CVE-2022-38627CRITICAL9.8Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered ...
CVE-2022-32665CRITICAL9.8In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of ...
CVE-2022-43931CRITICAL10Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4....
CVE-2022-47618CRITICAL9.8Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can ...
CVE-2022-39042CRITICAL9.8aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now