2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20696HIGH8.8A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated,...
CVE-2022-30079HIGH8.8Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/a...
CVE-2022-27593CRITICAL9.1An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Statio...
CVE-2022-3148MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
CVE-2022-3138MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository jgraph/drawio prior to 20.3.0.
CVE-2022-38400MEDIUM5.9Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use...
CVE-2022-38399MEDIUM6.8Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-...
CVE-2022-38394CRITICAL9.8Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a...
CVE-2022-38094HIGH8.8OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 al...
CVE-2022-36403HIGH7.8Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker...
CVE-2022-35273HIGH8.8OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allow...
CVE-2022-34869HIGH8.8Undocumented hidden command that can be executed from the telnet function of CentreCOM AR260S V2 firmware versions prior...
CVE-2022-33941CRITICAL9.8PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted me...
CVE-2022-28220HIGH7.5Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS com...
CVE-2022-25914CRITICAL9.8The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDocker...
CVE-2022-25897HIGH7.5The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limita...
CVE-2022-37146MEDIUM5.3The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login a...
CVE-2022-37145HIGH7.5The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configure...
CVE-2022-37144HIGH8.8The PlexTrac platform prior to API version 1.17.0 does not restrict excessive MFA TOTP submission attempts. An unauthent...
CVE-2022-38531HIGH8.8FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.
CVE-2022-37779HIGH7.2Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe...
CVE-2022-37778HIGH7.2Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe...
CVE-2022-37777HIGH7.2Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers 3.0.1.17 and earlier were discovered to contain a remote ...
CVE-2022-36588CRITICAL9.8In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused ...
CVE-2022-36586CRITICAL9.8In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now