2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4873CRITICAL9.8On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By p...
CVE-2022-4498CRITICAL9.8In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication...
CVE-2022-46176MEDIUM5.9Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key veri...
CVE-2022-41812Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2022-41811Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2022-41810Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2022-41809Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2022-4499HIGH7.5TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials i...
CVE-2022-4885MEDIUM5.9A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unkn...
CVE-2022-4457MEDIUM5.5Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijac...
CVE-2022-4428HIGH8support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privil...
CVE-2022-40615CRITICAL9.8 IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could sen...
CVE-2022-34335MEDIUM6.5 IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server res...
CVE-2022-4543MEDIUM5.5A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local atta...
CVE-2022-4415MEDIUM5.5A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not ...
CVE-2022-47864CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
CVE-2022-47862CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
CVE-2022-47861CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
CVE-2022-47860CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
CVE-2022-47859CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVE-2022-47866CRITICAL9.8Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
CVE-2022-47865CRITICAL9.8Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
CVE-2022-4696HIGH7.8There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If ...
CVE-2022-42967CRITICAL9.6Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This dire...
CVE-2022-34441CRITICAL9.8 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now