2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36070HIGH7.3Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes vario...
CVE-2022-36069HIGH7.3Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a regis...
CVE-2022-30078HIGH8.8NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0...
CVE-2022-30312MEDIUM6.5The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to F...
CVE-2022-1807HIGH7.2Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall ol...
CVE-2022-37780HIGH7.2Phicomm FIR151B A2, FIR302E A2, FIR300B A2, FIR303B A2 routers V3.0.1.17 were discovered to contain a remote command exe...
CVE-2022-36661MEDIUM6.5xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerab...
CVE-2022-36660CRITICAL9.8xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().
CVE-2022-36659MEDIUM6.5xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnera...
CVE-2022-36587CRITICAL9.8In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function ...
CVE-2022-36539HIGH7.5WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted calls to gain access to ...
CVE-2022-31414HIGH7.5D-Link DIR-1960 firmware DIR-1960_A1_1.11 was discovered to contain a buffer overflow via srtcat in prog.cgi. This vulne...
CVE-2022-3152HIGH8.8Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
CVE-2022-37731MEDIUM6.1ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing ...
CVE-2022-37730HIGH8.8In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to f...
CVE-2022-37108HIGH7.2An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with ...
CVE-2022-36271HIGH7.8Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker ...
CVE-2022-35513HIGH7.5The Blink1Control2 application <= 2.2.7 uses weak password encryption and an insecure method of storage.
CVE-2022-31167MEDIUM6.5XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with...
CVE-2022-31166HIGH8.8XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0...
CVE-2022-31149CRITICAL9.6ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. Th...
CVE-2022-40023HIGH7.5Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. ...
CVE-2022-37189HIGH7.5DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to ...
CVE-2022-31251MEDIUM6.3A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local a...
CVE-2022-31247CRITICAL9.1An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now