2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42471MEDIUM5.4An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In Fort...
CVE-2022-41336MEDIUM4.8An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 thro...
CVE-2022-39947HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
CVE-2022-35845HIGH8.8Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
CVE-2022-38766HIGH8.1The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for e...
CVE-2022-4663MEDIUM6.1The Members Import plugin for WordPress is vulnerable to Self Cross-Site Scripting via the user_login parameter in an im...
CVE-2022-4871HIGH7.2A vulnerability classified as problematic was found in ummmmm nflpick-em.com up to 2.2.x. This vulnerability affects the...
CVE-2022-43931CRITICAL10Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4....
CVE-2022-47908HIGH7.8Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the inform...
CVE-2022-47618CRITICAL9.8Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can ...
CVE-2022-47317HIGH7.8Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information an...
CVE-2022-46360HIGH7.8Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker ...
CVE-2022-46309MEDIUM6.5Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit...
CVE-2022-46306HIGH7.8ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters ...
CVE-2022-46305MEDIUM6.5ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vul...
CVE-2022-46304HIGH8.8ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. ...
CVE-2022-43448HIGH7.8Out-of-bounds write vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker...
CVE-2022-43438HIGH8.8The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as ...
CVE-2022-43437HIGH8.8The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticate...
CVE-2022-43436HIGH8.8The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker ...
CVE-2022-41645HIGH7.8Out-of-bounds read vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information and...
CVE-2022-40740HIGH7.2Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrat...
CVE-2022-39042CRITICAL9.8aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerabil...
CVE-2022-39041CRITICAL9.8aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can ...
CVE-2022-39040HIGH7.5aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now