2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-47377CRITICAL9.8Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivilege...
CVE-2022-46393CRITICAL9.8An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow ...
CVE-2022-45969CRITICAL9.8Alist v3.4.0 is vulnerable to Directory Traversal,
CVE-2022-40004CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted...
CVE-2022-46634CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p...
CVE-2022-46631CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled p...
CVE-2022-44588CRITICAL9.8Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.
CVE-2022-44236CRITICAL9.8Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.
CVE-2022-42842CRITICAL9.8The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ve...
CVE-2022-42837CRITICAL9.8An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in...
CVE-2022-47408CRITICAL9.1An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b...
CVE-2022-47406CRITICAL9.8An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x be...
CVE-2022-38488CRITICAL9.8logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
CVE-2022-31702CRITICAL9.8vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious act...
CVE-2022-46255CRITICAL9.8An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server ...
CVE-2022-46072CRITICAL9.8Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.
CVE-2022-46071CRITICAL9.8There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to by...
CVE-2022-46997CRITICAL9.8Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the req...
CVE-2022-46996CRITICAL9.8vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via ...
CVE-2022-46609CRITICAL9.8Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was disc...
CVE-2022-44832CRITICAL9.8D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTrigg...
CVE-2022-31358CRITICAL9A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attack...
CVE-2022-4494CRITICAL9.8A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is ...
CVE-2022-4493CRITICAL9.8A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUn...
CVE-2022-24377CRITICAL9.8The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt funct...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now