2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-40889CRITICAL9.8Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.
CVE-2022-3583CRITICAL9.8A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulner...
CVE-2022-3579CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Cashier Queuing System 1.0. This vulnerability affect...
CVE-2022-39056CRITICAL9.8RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can in...
CVE-2022-22241CRITICAL9.8An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthentica...
CVE-2022-42149CRITICAL9.8kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
CVE-2022-32176CRITICAL9In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution o...
CVE-2022-40055CRITICAL9.8An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force at...
CVE-2022-2992CRITICAL9.9A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows...
CVE-2022-2884CRITICAL9.9A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3...
CVE-2022-23770CRITICAL9.8This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of ce...
CVE-2022-23769CRITICAL9.8Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers...
CVE-2022-22128CRITICAL9.8Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer...
CVE-2022-0699CRITICAL9.8A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attack...
CVE-2022-42237CRITICAL9.8A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.
CVE-2022-42171CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.
CVE-2022-42170CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.
CVE-2022-42169CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.
CVE-2022-42168CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.
CVE-2022-42167CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.
CVE-2022-42166CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.
CVE-2022-42154CRITICAL9.8An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to e...
CVE-2022-42165CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.
CVE-2022-42164CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.
CVE-2022-42163CRITICAL9.8Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now