2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-39041CRITICAL9.8aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can ...
CVE-2022-39039CRITICAL9.8aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this...
CVE-2022-4357CRITICAL9.8The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-4298CRITICAL9.8The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user ...
CVE-2022-4297CRITICAL9.8The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a ...
CVE-2022-4099CRITICAL9.8The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using th...
CVE-2022-4059CRITICAL9.8The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it ...
CVE-2022-4049CRITICAL9.8The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL stat...
CVE-2022-3241CRITICAL9.8The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using t...
CVE-2022-42475CRITICAL9.8A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 ...
CVE-2022-34322CRITICAL9Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScri...
CVE-2022-48198CRITICAL9.8The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who contr...
CVE-2022-4866CRITICAL9Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4865CRITICAL9Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-48195CRITICAL9.8An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the...
CVE-2022-47128CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.
CVE-2022-47127CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet.
CVE-2022-47126CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.
CVE-2022-47125CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.
CVE-2022-47124CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.
CVE-2022-47123CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.
CVE-2022-47122CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd_5g parameter at /goform/WifiBasicSet.
CVE-2022-47121CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.
CVE-2022-47120CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
CVE-2022-47119CRITICAL9.8Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now