2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44951MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab f...
CVE-2022-44950MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func...
CVE-2022-44949MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func...
CVE-2022-44948MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group fea...
CVE-2022-44947MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feat...
CVE-2022-44946MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function ...
CVE-2022-44945CRITICAL9.8Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.
CVE-2022-44944MEDIUM5.4Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement f...
CVE-2022-44291CRITICAL9.8webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.
CVE-2022-44290CRITICAL9.8webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php...
CVE-2022-3086HIGH7.6Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers ...
CVE-2022-2642HIGH7.5Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out s...
CVE-2022-2641CRITICAL9.8Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an a...
CVE-2022-2640HIGH7.5The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulne...
CVE-2022-46167HIGH8.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed ...
CVE-2022-3520CRITICAL9.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
CVE-2022-46145CRITICAL9.8authentik is an open-source identity provider. Versions prior to 2022.11.2 and 2022.10.2 are vulnerable to unauthorized ...
CVE-2022-45672HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.
CVE-2022-45671HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRu...
CVE-2022-45670HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing func...
CVE-2022-45669HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet...
CVE-2022-45668MEDIUM6.5Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.
CVE-2022-45667MEDIUM6.5Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.
CVE-2022-45664HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the list parameter in the formwrlSSIDget functi...
CVE-2022-45663HIGH7.5Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterSet...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now