2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44197 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip. |
| CVE-2022-44196 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1. |
| CVE-2022-44194 | CRITICAL | 9.8 | 1.4% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec. |
| CVE-2022-44193 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , en... |
| CVE-2022-44191 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2. |
| CVE-2022-44190 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering. |
| CVE-2022-44188 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering. |
| CVE-2022-44187 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri. |
| CVE-2022-44186 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri. |
| CVE-2022-42989 | CRITICAL | 9 | 1.0% | Nov 22, 2022 | ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa... |
| CVE-2022-40189 | CRITICAL | 9.8 | 3.9% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-38649 | CRITICAL | 9.8 | 3.2% | Nov 22, 2022 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl... |
| CVE-2022-40602 | CRITICAL | 9.8 | 1.0% | Nov 22, 2022 | A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the ... |
| CVE-2022-36227 | CRITICAL | 9.8 | 1.9% | Nov 22, 2022 | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with ... |
| CVE-2022-43215 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde... |
| CVE-2022-43214 | CRITICAL | 9.8 | 0.9% | Nov 22, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr... |
| CVE-2022-41326 | CRITICAL | 9.8 | 1.4% | Nov 22, 2022 | The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbi... |
| CVE-2022-40842 | CRITICAL | 9.1 | 0.8% | Nov 22, 2022 | ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php. |
| CVE-2022-36180 | CRITICAL | 9.6 | 1.0% | Nov 22, 2022 | Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fus... |
| CVE-2022-36179 | CRITICAL | 9.8 | 1.1% | Nov 22, 2022 | Fusiondirectory 1.3 suffers from Improper Session Handling. |
| CVE-2022-44785 | CRITICAL | 9.8 | 0.8% | Nov 21, 2022 | An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection... |
| CVE-2022-41945 | CRITICAL | 9.8 | 0.8% | Nov 21, 2022 | super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spl... |
| CVE-2022-30258 | CRITICAL | 9.8 | 0.7% | Nov 21, 2022 | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resoluti... |
| CVE-2022-30257 | CRITICAL | 9.8 | 0.7% | Nov 21, 2022 | An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resoluti... |
| CVE-2022-43143 | CRITICAL | 9.6 | 0.8% | Nov 21, 2022 | A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now