2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36201CRITICAL9.8Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
CVE-2022-2898MEDIUM5.5Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow...
CVE-2022-2897HIGH7.8Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow...
CVE-2022-2896HIGH7.8Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.
CVE-2022-2895HIGH7.8Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based ...
CVE-2022-2894HIGH7.8Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted po...
CVE-2022-2892HIGH7.8Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-...
CVE-2022-36582HIGH7.2An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 a...
CVE-2022-36581HIGH7.5Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /a...
CVE-2022-36580HIGH7.2An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering Sys...
CVE-2022-36571HIGH7.2Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting.
CVE-2022-36570HIGH7.2Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg.
CVE-2022-36569HIGH8.8Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCf...
CVE-2022-36568HIGH8.8Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList.
CVE-2022-36048MEDIUM4.3Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying...
CVE-2022-34383HIGH8.2Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A loca...
CVE-2022-34373HIGH7.8Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability...
CVE-2022-31233HIGH8Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user...
CVE-2022-1841MEDIUM5.3In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-boun...
CVE-2022-37128CRITICAL9.8In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
CVE-2022-36046MEDIUM5.3Next.js is a React framework that can provide building blocks to create web applications. All of the following must be t...
CVE-2022-38812MEDIUM6.5AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CVE-2022-38153MEDIUM5.9An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is e...
CVE-2022-37184HIGH8.8The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authe...
CVE-2022-37183MEDIUM6.1Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now