2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41923 | CRITICAL | 9.8 | 1.7% | Nov 23, 2022 | Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to... |
| CVE-2022-41875 | CRITICAL | 9.8 | 1.6% | Nov 23, 2022 | A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via spe... |
| CVE-2022-41922 | CRITICAL | 9.8 | 1.1% | Nov 23, 2022 | `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(... |
| CVE-2022-44255 | CRITICAL | 9.8 | 2.2% | Nov 23, 2022 | TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post d... |
| CVE-2022-44252 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting ... |
| CVE-2022-44251 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function. |
| CVE-2022-44250 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg func... |
| CVE-2022-44249 | CRITICAL | 9.8 | 1.8% | Nov 23, 2022 | TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFil... |
| CVE-2022-44139 | CRITICAL | 9.8 | 0.8% | Nov 23, 2022 | Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php. |
| CVE-2022-45462 | CRITICAL | 9.8 | 2.8% | Nov 23, 2022 | Alarm instance management has command injection when there is a specific command configured. It is only for logged-in us... |
| CVE-2022-43213 | CRITICAL | 9.8 | 0.8% | Nov 23, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.ph... |
| CVE-2022-4116 | CRITICAL | 9.8 | 32.5% | Nov 22, 2022 | A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by... |
| CVE-2022-43212 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr... |
| CVE-2022-39070 | CRITICAL | 9.8 | 0.8% | Nov 22, 2022 | There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote a... |
| CVE-2022-44808 | CRITICAL | 9.8 | 3.8% | Nov 22, 2022 | A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an... |
| CVE-2022-44807 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString. |
| CVE-2022-44806 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow. |
| CVE-2022-44804 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function. |
| CVE-2022-44801 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control. |
| CVE-2022-44202 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow. |
| CVE-2022-44201 | CRITICAL | 9.8 | 1.2% | Nov 22, 2022 | D-Link DIR823G 1.02B05 is vulnerable to Commad Injection. |
| CVE-2022-44184 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec. |
| CVE-2022-44200 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_se... |
| CVE-2022-44199 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. |
| CVE-2022-44198 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now