2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45536MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php....
CVE-2022-45535MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. ...
CVE-2022-45529MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl...
CVE-2022-45331HIGH7.5AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnera...
CVE-2022-45330HIGH7.5AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This...
CVE-2022-39397MEDIUM4.3aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret wi...
CVE-2022-41919HIGH8.8Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Ty...
CVE-2022-39199MEDIUM5.9immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to disting...
CVE-2022-2791HIGH7.8Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File w...
CVE-2022-4116CRITICAL9.8A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by...
CVE-2022-41943HIGH7.2sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver ...
CVE-2022-41942HIGH7.8Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the...
CVE-2022-40228MEDIUM5.4 IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5....
CVE-2022-3500MEDIUM5.1A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled ...
CVE-2022-43212CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOr...
CVE-2022-41950HIGH7.8super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerabilit...
CVE-2022-39070CRITICAL9.8There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote a...
CVE-2022-39067MEDIUM6.5There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interf...
CVE-2022-39066HIGH8.8There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phon...
CVE-2022-44737HIGH8.8Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plu...
CVE-2022-41952MEDIUM5.3Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs...
CVE-2022-44808CRITICAL9.8A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an...
CVE-2022-44807CRITICAL9.8D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.
CVE-2022-44806CRITICAL9.8D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.
CVE-2022-44804CRITICAL9.8D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now