2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44290 | CRITICAL | 9.8 | 3.7% | Dec 2, 2022 | webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php... |
| CVE-2022-2641 | CRITICAL | 9.8 | 0.5% | Dec 2, 2022 | Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an a... |
| CVE-2022-3520 | CRITICAL | 9.8 | 1.0% | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. |
| CVE-2022-46145 | CRITICAL | 9.8 | 1.2% | Dec 2, 2022 | authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized ... |
| CVE-2022-44367 | CRITICAL | 9.8 | 0.9% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo. |
| CVE-2022-44366 | CRITICAL | 9.8 | 9.9% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo. |
| CVE-2022-44365 | CRITICAL | 9.8 | 0.9% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd. |
| CVE-2022-44363 | CRITICAL | 9.8 | 0.8% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo. |
| CVE-2022-44362 | CRITICAL | 9.8 | 0.9% | Dec 2, 2022 | Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule. |
| CVE-2022-45482 | CRITICAL | 9.8 | 1.3% | Dec 2, 2022 | Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticat... |
| CVE-2022-46366 | CRITICAL | 9.8 | 3.6% | Dec 2, 2022 | Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to... |
| CVE-2022-2807 | CRITICAL | 9.8 | 0.6% | Dec 2, 2022 | SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects... |
| CVE-2022-44930 | CRITICAL | 9.8 | 2.5% | Dec 2, 2022 | D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function. |
| CVE-2022-44929 | CRITICAL | 9.8 | 1.1% | Dec 2, 2022 | An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitr... |
| CVE-2022-44928 | CRITICAL | 9.8 | 2.7% | Dec 2, 2022 | D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function. |
| CVE-2022-43325 | CRITICAL | 9.8 | 3.2% | Dec 2, 2022 | An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MP... |
| CVE-2022-43333 | CRITICAL | 9.8 | 1.6% | Dec 1, 2022 | Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the... |
| CVE-2022-4257 | CRITICAL | 9.8 | 43.9% | Dec 1, 2022 | A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknow... |
| CVE-2022-37016 | CRITICAL | 9.8 | 0.7% | Dec 1, 2022 | Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type... |
| CVE-2022-30528 | CRITICAL | 9.8 | 1.2% | Dec 1, 2022 | SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attacke... |
| CVE-2022-3270 | CRITICAL | 9.8 | 1.1% | Dec 1, 2022 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which c... |
| CVE-2022-1471 | CRITICAL | 9.8 | 99.6% | Dec 1, 2022 | SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing ... |
| CVE-2022-4221 | CRITICAL | 9.8 | 4.8% | Dec 1, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25... |
| CVE-2022-4248 | CRITICAL | 9.8 | 0.5% | Dec 1, 2022 | A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects som... |
| CVE-2022-4247 | CRITICAL | 9.8 | 0.5% | Dec 1, 2022 | A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now