2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23688MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23687MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23686MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23684HIGH8.8A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only p...
CVE-2022-23683HIGH7.2Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful...
CVE-2022-23682HIGH7.8Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ...
CVE-2022-23681HIGH7.8Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ...
CVE-2022-23680HIGH8.8AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac...
CVE-2022-23679HIGH8.8AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac...
CVE-2022-23678MEDIUM5.9A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communic...
CVE-2022-23451HIGH8.1An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any ...
CVE-2022-1697LOW3.9Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted p...
CVE-2022-1628MEDIUM5.4The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and ...
CVE-2022-1260Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-0844Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-40112HIGH7.5TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in bin...
CVE-2022-40111CRITICAL9.8In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware...
CVE-2022-40110HIGH7.5TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.
CVE-2022-40109CRITICAL9.8TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.
CVE-2022-37843CRITICAL9.8In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for e...
CVE-2022-37842CRITICAL9.8In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vu...
CVE-2022-37841HIGH7.5In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
CVE-2022-37840CRITICAL9.8In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.
CVE-2022-37839CRITICAL9.8TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi.
CVE-2022-36584CRITICAL9.8In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now