2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23466MEDIUM5.4teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to...
CVE-2022-45326MEDIUM4.9An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote...
CVE-2022-40680MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.1...
CVE-2022-38379MEDIUM5.4Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allo...
CVE-2022-35843CRITICAL9.8An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7....
CVE-2022-33876MEDIUM6.5Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through ...
CVE-2022-33875HIGH8.8An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiA...
CVE-2022-30305HIGH7.5An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1...
CVE-2022-46382HIGH8.8RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h...
CVE-2022-44289HIGH8.8Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
CVE-2022-43363MEDIUM6.1Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties...
CVE-2022-41325HIGH7.8An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user...
CVE-2022-38123HIGH7.2Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrato...
CVE-2022-46383CRITICAL9.8RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h...
CVE-2022-40209MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xylus Themes WP Smart Import plugin <= 1.0.2 on WordPress.
CVE-2022-4300HIGH8.8A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the f...
CVE-2022-4296MEDIUM5.5A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the co...
CVE-2022-42782MEDIUM5.5In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.
CVE-2022-42781MEDIUM5.5In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42780MEDIUM5.5In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42779MEDIUM5.5In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
CVE-2022-42778HIGH7.8In windows manager service, there is a missing permission check. This could lead to set up windows manager service with ...
CVE-2022-42777HIGH7.8In power management service, there is a missing permission check. This could lead to set up power management service wit...
CVE-2022-42776HIGH7.8In UscAIEngine service, there is a missing permission check. This could lead to set up UscAIEngine service with no addit...
CVE-2022-42775MEDIUM5.5In camera driver, there is a possible memory corruption due to improper locking. This could lead to local denial of serv...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now