2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44373HIGH8.8A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1...
CVE-2022-44351CRITICAL9.8Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.
CVE-2022-43581HIGH8.8IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i...
CVE-2022-44393HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.
CVE-2022-44371CRITICAL9.8hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
CVE-2022-44361MEDIUM5.4An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php.
CVE-2022-41735MEDIUM6.1IBM Business Process Manager 21.0.1 through 21.0.3.1, 20.0.0.1 through 20.0.0.2 19.0.0.1 through 19.0.0.3 is vulnerable ...
CVE-2022-41720HIGH7.5On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide ...
CVE-2022-45217MEDIUM5.4A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary ...
CVE-2022-45910MEDIUM5.3Improper neutralization of special elements used in an LDAP query ('LDAP Injection') vulnerability in ActiveDirectory an...
CVE-2022-42458CRITICAL9.8Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a ...
CVE-2022-40966HIGH8.8Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass aut...
CVE-2022-39044MEDIUM6.8Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an admini...
CVE-2022-34840MEDIUM6.5Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to al...
CVE-2022-46742CRITICAL9.8Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
CVE-2022-46741CRITICAL9.1Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. 
CVE-2022-4322HIGH7.2A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecu...
CVE-2022-45122MEDIUM6.1Cross-site scripting vulnerability in Movable Type Movable Type 7 r.5301 and earlier (Movable Type 7 Series), Movable Ty...
CVE-2022-45113MEDIUM6.5Improper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to acces...
CVE-2022-44620HIGH8.8Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earli...
CVE-2022-44608HIGH7.5Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated at...
CVE-2022-44606HIGH8.8OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ...
CVE-2022-43668MEDIUM6.1Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript co...
CVE-2022-43667HIGH7.8Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disc...
CVE-2022-43660HIGH7.2Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authentic...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now