2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-45907CRITICAL9.8In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is ...
CVE-2022-44844CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass paramete...
CVE-2022-44843CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port paramete...
CVE-2022-45152CRITICAL9.1A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient valid...
CVE-2022-41158CRITICAL9.8Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A...
CVE-2022-41157CRITICAL9.8A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vul...
CVE-2022-45476CRITICAL9.8Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returni...
CVE-2022-41705CRITICAL9.8Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is...
CVE-2022-45207CRITICAL9.8Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
CVE-2022-45206CRITICAL9.8Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
CVE-2022-37721CRITICAL9PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a...
CVE-2022-37720CRITICAL9Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an aut...
CVE-2022-36133CRITICAL9.1The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication ...
CVE-2022-4135CRITICAL9.6Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the r...
CVE-2022-29830CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M...
CVE-2022-2650CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
CVE-2022-4088CRITICAL9.8A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some u...
CVE-2022-4136CRITICAL9.8Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host ...
CVE-2022-45872CRITICAL9.8iTerm2 before 3.4.18 mishandles a DECRQSS response.
CVE-2022-45276CRITICAL9.8An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Admi...
CVE-2022-44120CRITICAL9.8dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.
CVE-2022-44118CRITICAL9.8dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.
CVE-2022-44117CRITICAL9.8Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa...
CVE-2022-43196CRITICAL9.1dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
CVE-2022-41924CRITICAL9.6A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now