2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44646MEDIUM5.3In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
CVE-2022-44624HIGH7.5In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained sp...
CVE-2022-44623HIGH7.5In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner setting...
CVE-2022-44622MEDIUM5.3In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
CVE-2022-43109CRITICAL9.8D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin...
CVE-2022-43108CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal...
CVE-2022-43107CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagem...
CVE-2022-43106CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWi...
CVE-2022-43105CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...
CVE-2022-43104CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWire...
CVE-2022-43103CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand funct...
CVE-2022-43102CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime f...
CVE-2022-43101CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName...
CVE-2022-39382CRITICAL9.8Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `...
CVE-2022-39276MEDIUM5.3GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39262MEDIUM4.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package, GLPI a...
CVE-2022-39234HIGH8.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-41435MEDIUM5.4OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerabilit...
CVE-2022-32287HIGH7.5A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows ...
CVE-2022-44638HIGH8.8In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edge...
CVE-2022-44586MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) in Ayoub Media AM-HiLi plugin <= 1.0 on WordPress.
CVE-2022-44576MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in AgentEasy Properties plugin <= 1.0.4 on WordPress.
CVE-2022-24945Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3181HIGH7.5An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malform...
CVE-2022-43068HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now