2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-44197CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.
CVE-2022-44196CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.
CVE-2022-44194CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.
CVE-2022-44193CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , en...
CVE-2022-44191CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.
CVE-2022-44190CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.
CVE-2022-44188CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.
CVE-2022-44187CRITICAL9.8Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.
CVE-2022-44186CRITICAL9.8Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.
CVE-2022-42989CRITICAL9ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa...
CVE-2022-40189CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-38649CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-40602CRITICAL9.8A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the ...
CVE-2022-36227CRITICAL9.8In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with ...
CVE-2022-43215CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde...
CVE-2022-43214CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr...
CVE-2022-41326CRITICAL9.8The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbi...
CVE-2022-40842CRITICAL9.1ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
CVE-2022-36180CRITICAL9.6Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fus...
CVE-2022-36179CRITICAL9.8Fusiondirectory 1.3 suffers from Improper Session Handling.
CVE-2022-44785CRITICAL9.8An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection...
CVE-2022-41945CRITICAL9.8super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spl...
CVE-2022-30258CRITICAL9.8An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resoluti...
CVE-2022-30257CRITICAL9.8An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resoluti...
CVE-2022-43143CRITICAL9.6A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now