2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38088MEDIUM6.5A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-21072...
CVE-2022-38066HIGH8.8An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-1410...
CVE-2022-36279HIGH8.8A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1....
CVE-2022-4510HIGH7.8A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By craf...
CVE-2022-4092HIGH8An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to cr...
CVE-2022-4054MEDIUM5.5An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting fro...
CVE-2022-48199HIGH8.8SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges...
CVE-2022-47767CRITICAL9.8A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to t...
CVE-2022-47615CRITICAL9.8Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2022-47100HIGH7.5A vulnerability in Sengled Smart bulb 0x0000024 allows attackers to arbitrarily perform a factory reset on the device vi...
CVE-2022-47073MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbit...
CVE-2022-47052MEDIUM6.1The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can b...
CVE-2022-47042HIGH8.8MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/wri...
CVE-2022-47040HIGH7.8An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running ...
CVE-2022-46999CRITICAL9.8Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserCont...
CVE-2022-46998CRITICAL9.8An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).
CVE-2022-46957MEDIUM6.1Sourcecodester.com Online Graduate Tracer System V 1.0.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-46624MEDIUM6.1A cross-site scripting (XSS) vulnerability in Online Graduate Tracer System v1.0.0 allows attackers to execute arbitrary...
CVE-2022-46128MEDIUM6.1phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=.
CVE-2022-45920HIGH7.5In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.
CVE-2022-45820HIGH8.8SQL Injection (SQLi) vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2022-45808CRITICAL9.8SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.
CVE-2022-45730MEDIUM6.1A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar...
CVE-2022-44297CRITICAL9.8SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CVE-2022-44018HIGH7.5In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now