2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44363CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.
CVE-2022-44362CRITICAL9.8Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
CVE-2022-44348HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.
CVE-2022-44347HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
CVE-2022-44345HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
CVE-2022-44277HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
CVE-2022-3591HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0789.
CVE-2022-4271MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.
CVE-2022-45483MEDIUM5.9Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all dat...
CVE-2022-45482CRITICAL9.8Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticat...
CVE-2022-45480MEDIUM5.9PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected devi...
CVE-2022-43272HIGH7.5DCMTK v3.6.7 was discovered to contain a memory leak via the T_ASC_Association object.
CVE-2022-46159MEDIUM4.3Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be...
CVE-2022-45215MEDIUM5.4A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary ...
CVE-2022-46366CRITICAL9.8Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to...
CVE-2022-4270LOW2.6Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permi...
CVE-2022-2808HIGH8.8Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows...
CVE-2022-2807CRITICAL9.8SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects...
CVE-2022-45562HIGH8.8Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system s...
CVE-2022-44930CRITICAL9.8D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
CVE-2022-44929CRITICAL9.8An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitr...
CVE-2022-44928CRITICAL9.8D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
CVE-2022-43325CRITICAL9.8An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MP...
CVE-2022-44212MEDIUM5.9In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
CVE-2022-44211HIGH7.4In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now