2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-41923CRITICAL9.8Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to...
CVE-2022-41875CRITICAL9.8A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via spe...
CVE-2022-41922CRITICAL9.8`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize(...
CVE-2022-44255CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post d...
CVE-2022-44252CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting ...
CVE-2022-44251CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
CVE-2022-44250CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg func...
CVE-2022-44249CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFil...
CVE-2022-44139CRITICAL9.8Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
CVE-2022-45462CRITICAL9.8Alarm instance management has command injection when there is a specific command configured. It is only for logged-in us...
CVE-2022-43213CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.ph...
CVE-2022-4116CRITICAL9.8A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by...
CVE-2022-43212CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr...
CVE-2022-39070CRITICAL9.8There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote a...
CVE-2022-44808CRITICAL9.8A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an...
CVE-2022-44807CRITICAL9.8D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.
CVE-2022-44806CRITICAL9.8D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.
CVE-2022-44804CRITICAL9.8D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.
CVE-2022-44801CRITICAL9.8D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.
CVE-2022-44202CRITICAL9.8D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.
CVE-2022-44201CRITICAL9.8D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.
CVE-2022-44184CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.
CVE-2022-44200CRITICAL9.8Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_se...
CVE-2022-44199CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
CVE-2022-44198CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now