2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42086MEDIUM6.5Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function T...
CVE-2022-42081HIGH7.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via sched_end_time para...
CVE-2022-42080HIGH7.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a heap overflow via sched_start_time par...
CVE-2022-42079HIGH7.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 was discovered to contain a stack overflow via the function formWi...
CVE-2022-42078MEDIUM6.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr...
CVE-2022-42077MEDIUM6.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr...
CVE-2022-2249MEDIUM6.7Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local ad...
CVE-2022-41403CRITICAL9.8OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at ...
CVE-2022-28887HIGH7.5Multiple Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl.dll un...
CVE-2022-0030HIGH8.1An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacke...
CVE-2022-3467CRITICAL9.8A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality...
CVE-2022-33106CRITICAL9.8WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force...
CVE-2022-42715MEDIUM6.1A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted C...
CVE-2022-40871CRITICAL9.8Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installat...
CVE-2022-37614CRITICAL9.8Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5c...
CVE-2022-3465CRITICAL9.8A vulnerability classified as critical was found in Mediabridge Medialink. This vulnerability affects unknown code of th...
CVE-2022-3464MEDIUM6.1A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file...
CVE-2022-40664CRITICAL9.8Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatc...
CVE-2022-3458CRITICAL9.8A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affect...
CVE-2022-2720MEDIUM5.3In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, se...
CVE-2022-42711CRITICAL9.6In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious ...
CVE-2022-40469HIGH8.8iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
CVE-2022-37611CRITICAL9.8Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.
CVE-2022-41606MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid ...
CVE-2022-41532HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now