2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43709MEDIUM4.9MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify...
CVE-2022-43708MEDIUM6.1MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow atta...
CVE-2022-43707MEDIUM6.1MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attacker...
CVE-2022-44788MEDIUM6.5An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESS...
CVE-2022-44787MEDIUM6.1An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scr...
CVE-2022-44786HIGH7.5An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any pag...
CVE-2022-44785CRITICAL9.8An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection...
CVE-2022-44784HIGH8.8An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of service...
CVE-2022-41945CRITICAL9.8super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spl...
CVE-2022-30258CRITICAL9.8An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resoluti...
CVE-2022-30257CRITICAL9.8An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resoluti...
CVE-2022-43143CRITICAL9.6A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts ...
CVE-2022-42096MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content...
CVE-2022-4105MEDIUM5.4A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a...
CVE-2022-3388HIGH7.8An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An auth...
CVE-2022-44830HIGH7.8Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the Firs...
CVE-2022-44183CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.
CVE-2022-44180CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.
CVE-2022-44178CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.
CVE-2022-44177CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.
CVE-2022-44176CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.
CVE-2022-44175CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
CVE-2022-44174CRITICAL9.8Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.
CVE-2022-44172CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.
CVE-2022-44171CRITICAL9.8Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now