2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-43305CRITICAL9.8The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third part...
CVE-2022-43304CRITICAL9.8The d8s-timer for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party...
CVE-2022-43303CRITICAL9.8The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third par...
CVE-2022-42920CRITICAL9.8Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However...
CVE-2022-37865CRITICAL9.1With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fl...
CVE-2022-3481CRITICAL9.8The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using ...
CVE-2022-3463CRITICAL9.8The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries a...
CVE-2022-44797CRITICAL9.8btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witn...
CVE-2022-44796CRITICAL9.8An issue was discovered in Object First Ootbi BETA build 1.0.7.712. The authorization service has a flow that allows get...
CVE-2022-42905CRITICAL9.1In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 cl...
CVE-2022-44544CRITICAL9.8Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PD...
CVE-2022-3868CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an u...
CVE-2022-39344CRITICAL9.8Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre...
CVE-2022-31691CRITICAL9.8Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI...
CVE-2022-3023CRITICAL9.8Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.
CVE-2022-38168CRITICAL9.1Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un...
CVE-2022-42744CRITICAL9.8CandidATS version 3.0.0 allows an external attacker to perform CRUD operations on the application databases. This is pos...
CVE-2022-40747CRITICAL9.1"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing X...
CVE-2022-22425CRITICAL9.8"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbi...
CVE-2022-39323CRITICAL9.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-43109CRITICAL9.8D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettin...
CVE-2022-43108CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewal...
CVE-2022-43107CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagem...
CVE-2022-43106CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWi...
CVE-2022-43105CRITICAL9.8Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now