2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41527HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser para...
CVE-2022-41526HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter i...
CVE-2022-41525CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg fu...
CVE-2022-41524HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, a...
CVE-2022-41523HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parame...
CVE-2022-41522CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" funct...
CVE-2022-42457HIGH7.2Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update...
CVE-2022-42250HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=...
CVE-2022-42249HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
CVE-2022-42243HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id...
CVE-2022-42242HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
CVE-2022-42241HIGH7.2Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
CVE-2022-41853CRITICAL9.8Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input ma...
CVE-2022-41852Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-41556HIGH7.5A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exh...
CVE-2022-41521HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort pa...
CVE-2022-41520HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter...
CVE-2022-41518CRITICAL9.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwa...
CVE-2022-41517HIGH8.8TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLangu...
CVE-2022-41294MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing...
CVE-2022-40895CRITICAL9.1In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, ...
CVE-2022-40161Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-40160MEDIUM6.5** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i...
CVE-2022-40159MEDIUM6.5** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i...
CVE-2022-40158Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now