2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-50994CRITICAL9.2DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han...
CVE-2022-45899MEDIUM6.5Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as...
CVE-2022-26523MEDIUM5.3The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ...
CVE-2022-26522HIGH7.8The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ...
CVE-2022-23961MEDIUM6.1In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability...
CVE-2022-50993CRITICAL9.8Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability ...
CVE-2022-50992HIGH8.7Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet i...
CVE-2022-4987HIGH7.3Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of...
CVE-2022-4986HIGH8.7Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device t...
CVE-2022-4977Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2022-4947Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-32111. Reason: This candidate is a ...
CVE-2022-41650MEDIUM6.5Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.Thi...
CVE-2022-50981CRITICAL9.8An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password b...
CVE-2022-50980MEDIUM6.5A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre...
CVE-2022-50979MEDIUM6.5An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr...
CVE-2022-50978HIGH7.5An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres...
CVE-2022-50977HIGH7.5An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres...
CVE-2022-50976HIGH7.7A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.
CVE-2022-50975HIGH8.8An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the...
CVE-2022-50952MEDIUM6.4Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Nam...
CVE-2022-50951MEDIUM6.4WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject...
CVE-2022-50950HIGH7.1Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths w...
CVE-2022-50942MEDIUM5.4Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malic...
CVE-2022-50941MEDIUM6.4BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious ...
CVE-2022-50940MEDIUM6.4Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now