2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27064 | HIGH | 8.8 | 2.5% | Apr 8, 2022 | Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerabi... |
| CVE-2022-27061 | HIGH | 7.2 | 2.5% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Ad... |
| CVE-2022-1219 | HIGH | 7.5 | 1.4% | Apr 8, 2022 | SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is ca... |
| CVE-2022-28796 | HIGH | 7 | 0.3% | Apr 8, 2022 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a tr... |
| CVE-2022-26675 | HIGH | 7.5 | 2.1% | Apr 7, 2022 | aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass aut... |
| CVE-2022-26671 | HIGH | 7.3 | 0.9% | Apr 7, 2022 | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated... |
| CVE-2022-26670 | HIGH | 8.8 | 1.5% | Apr 7, 2022 | D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attack... |
| CVE-2022-25597 | HIGH | 8.8 | 0.8% | Apr 7, 2022 | ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unaut... |
| CVE-2022-25596 | HIGH | 8.8 | 0.6% | Apr 7, 2022 | ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for... |
| CVE-2022-23973 | HIGH | 8.8 | 0.6% | Apr 7, 2022 | ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient val... |
| CVE-2022-23972 | HIGH | 8.8 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An u... |
| CVE-2022-23971 | HIGH | 8.1 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special charac... |
| CVE-2022-23970 | HIGH | 8.1 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special charac... |
| CVE-2022-22519 | HIGH | 7.5 | 1.4% | Apr 7, 2022 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulti... |
| CVE-2022-22517 | HIGH | 7.5 | 1.3% | Apr 7, 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a v... |
| CVE-2022-22516 | HIGH | 7.8 | 0.3% | Apr 7, 2022 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write ... |
| CVE-2022-22515 | HIGH | 8.1 | 1.1% | Apr 7, 2022 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vuln... |
| CVE-2022-22514 | HIGH | 7.1 | 0.9% | Apr 7, 2022 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can sub... |
| CVE-2022-0935 | HIGH | 8.8 | 1.3% | Apr 7, 2022 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. |
| CVE-2022-0677 | HIGH | 7.5 | 1.2% | Apr 7, 2022 | Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint... |
| CVE-2022-26627 | HIGH | 8.8 | 1.4% | Apr 7, 2022 | Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows ... |
| CVE-2022-26607 | HIGH | 7.2 | 2.4% | Apr 6, 2022 | A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbit... |
| CVE-2022-26605 | HIGH | 8.8 | 1.0% | Apr 6, 2022 | eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality. |
| CVE-2022-26591 | HIGH | 7.5 | 1.1% | Apr 6, 2022 | FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a ... |
| CVE-2022-20774 | HIGH | 8.1 | 0.4% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform F... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now