2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42972HIGH7.8A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege e...
CVE-2022-42971CRITICAL9.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution w...
CVE-2022-42970CRITICAL9.8A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionali...
CVE-2022-2329CRITICAL9.8A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to d...
CVE-2022-24324CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflo...
CVE-2022-4206MEDIUM6.5A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102,...
CVE-2022-47770CRITICAL9.8Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.
CVE-2022-47769CRITICAL9.8An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to u...
CVE-2022-47768HIGH7.5Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.
CVE-2022-31902MEDIUM5.5Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
CVE-2022-48161HIGH7.5Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down....
CVE-2022-47873CRITICAL9.8Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
CVE-2022-45494HIGH7.8Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b15...
CVE-2022-45297CRITICAL9.8EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
CVE-2022-37708Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-32984HIGH7.5BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale a...
CVE-2022-47854CRITICAL9.8i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.
CVE-2022-47701MEDIUM6.1COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross...
CVE-2022-47700HIGH7.5COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerab...
CVE-2022-47699CRITICAL9.8COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incor...
CVE-2022-47698MEDIUM6.1COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross...
CVE-2022-47697CRITICAL9.8COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerab...
CVE-2022-45172CRITICAL9.8An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/re...
CVE-2022-47780CRITICAL9.8SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.
CVE-2022-47035CRITICAL9.8Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now