2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36111MEDIUM5.3immudb is a database with built-in cryptographic proof and verification. In versions prior to 1.4.1, a malicious immudb ...
CVE-2022-23740HIGH8.8CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterpri...
CVE-2022-38115MEDIUM5.3Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
CVE-2022-38114MEDIUM6.1This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lea...
CVE-2022-38113MEDIUM5.3This vulnerability discloses build and services versions in the server response header.
CVE-2022-35501MEDIUM5.4Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the du...
CVE-2022-44280MEDIUM6.5Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
CVE-2022-44278HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.
CVE-2022-44260HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the se...
CVE-2022-44259HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTim...
CVE-2022-44258HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTra...
CVE-2022-44257HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setO...
CVE-2022-44256HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLangua...
CVE-2022-44255CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post d...
CVE-2022-44254HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg...
CVE-2022-44253HIGH8.8TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosi...
CVE-2022-44252CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting ...
CVE-2022-44251CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
CVE-2022-44250CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg func...
CVE-2022-44249CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFil...
CVE-2022-44139CRITICAL9.8Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
CVE-2022-45151MEDIUM5.4The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied dat...
CVE-2022-45150MEDIUM6.1A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitizati...
CVE-2022-45149MEDIUM5.4A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course red...
CVE-2022-42896HIGH8.8There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now