2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-44290CRITICAL9.8webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php...
CVE-2022-2641CRITICAL9.8Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an a...
CVE-2022-3520CRITICAL9.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
CVE-2022-46145CRITICAL9.8authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized ...
CVE-2022-44367CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.
CVE-2022-44366CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.
CVE-2022-44365CRITICAL9.8Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.
CVE-2022-44363CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.
CVE-2022-44362CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
CVE-2022-45482CRITICAL9.8Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticat...
CVE-2022-46366CRITICAL9.8Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to...
CVE-2022-2807CRITICAL9.8SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects...
CVE-2022-44930CRITICAL9.8D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
CVE-2022-44929CRITICAL9.8An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitr...
CVE-2022-44928CRITICAL9.8D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
CVE-2022-43325CRITICAL9.8An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MP...
CVE-2022-43333CRITICAL9.8Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the...
CVE-2022-4257CRITICAL9.8A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknow...
CVE-2022-37016CRITICAL9.8Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type...
CVE-2022-30528CRITICAL9.8SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attacke...
CVE-2022-3270CRITICAL9.8In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which c...
CVE-2022-1471CRITICAL9.8SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing ...
CVE-2022-4221CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25...
CVE-2022-4248CRITICAL9.8A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects som...
CVE-2022-4247CRITICAL9.8A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now