2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-50994 | CRITICAL | 9.2 | 1.4% | May 8, 2026 | DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han... |
| CVE-2022-45899 | MEDIUM | 6.5 | 0.8% | May 8, 2026 | Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as... |
| CVE-2022-26523 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ... |
| CVE-2022-26522 | HIGH | 7.8 | 0.2% | May 8, 2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ... |
| CVE-2022-23961 | MEDIUM | 6.1 | 0.2% | May 8, 2026 | In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability... |
| CVE-2022-50993 | CRITICAL | 9.8 | 0.8% | Apr 30, 2026 | Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability ... |
| CVE-2022-50992 | HIGH | 8.7 | 0.7% | Apr 30, 2026 | Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet i... |
| CVE-2022-4987 | HIGH | 7.3 | 0.1% | Apr 3, 2026 | Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of... |
| CVE-2022-4986 | HIGH | 8.7 | 0.4% | Apr 2, 2026 | Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device t... |
| CVE-2022-4977 | — | — | — | Mar 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2022-4947 | — | — | — | Mar 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-32111. Reason: This candidate is a ... |
| CVE-2022-41650 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.Thi... |
| CVE-2022-50981 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b... |
| CVE-2022-50980 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre... |
| CVE-2022-50979 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr... |
| CVE-2022-50978 | HIGH | 7.5 | 0.4% | Feb 2, 2026 | An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres... |
| CVE-2022-50977 | HIGH | 7.5 | 0.4% | Feb 2, 2026 | An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres... |
| CVE-2022-50976 | HIGH | 7.7 | 0.1% | Feb 2, 2026 | A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB. |
| CVE-2022-50975 | HIGH | 8.8 | 0.2% | Feb 2, 2026 | An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the... |
| CVE-2022-50952 | MEDIUM | 6.4 | 0.2% | Feb 1, 2026 | Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Nam... |
| CVE-2022-50951 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject... |
| CVE-2022-50950 | HIGH | 7.1 | 0.9% | Feb 1, 2026 | Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w... |
| CVE-2022-50942 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malic... |
| CVE-2022-50941 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious ... |
| CVE-2022-50940 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now