2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35977MEDIUM5.5Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT...
CVE-2022-38112HIGH7.5In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2022-38110MEDIUM5.4In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated r...
CVE-2022-47747HIGH7.5kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
CVE-2022-47732HIGH7.5In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and downl...
CVE-2022-43704MEDIUM5.9The Sinilink XY-WFT1 WiFi Remote Thermostat, running firmware 1.3.6, allows an attacker to bypass the intended requireme...
CVE-2022-27918Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-27917Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-27916Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-27915Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-25631HIGH7.8Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnera...
CVE-2022-48126CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username para...
CVE-2022-48125CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password para...
CVE-2022-48124CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName para...
CVE-2022-48123CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername pa...
CVE-2022-48122CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid para...
CVE-2022-48121CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits param...
CVE-2022-43959MEDIUM4.9Insufficiently Protected Credentials in the AD/LDAP server settings in 1C-Bitrix Bitrix24 through 22.200.200 allow remot...
CVE-2022-41441MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o...
CVE-2022-40267CRITICAL9.1Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F S...
CVE-2022-48191HIGH7A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malic...
CVE-2022-20967MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re...
CVE-2022-20966MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re...
CVE-2022-20965MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re...
CVE-2022-20964HIGH8.8A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now