2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36201 | CRITICAL | 9.8 | 1.7% | Aug 31, 2022 | Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php. |
| CVE-2022-2898 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow... |
| CVE-2022-2897 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow... |
| CVE-2022-2896 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. |
| CVE-2022-2895 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based ... |
| CVE-2022-2894 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted po... |
| CVE-2022-2892 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-... |
| CVE-2022-36582 | HIGH | 7.2 | 1.1% | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 a... |
| CVE-2022-36581 | HIGH | 7.5 | 0.8% | Aug 31, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /a... |
| CVE-2022-36580 | HIGH | 7.2 | 1.1% | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering Sys... |
| CVE-2022-36571 | HIGH | 7.2 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting. |
| CVE-2022-36570 | HIGH | 7.2 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg. |
| CVE-2022-36569 | HIGH | 8.8 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCf... |
| CVE-2022-36568 | HIGH | 8.8 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList. |
| CVE-2022-36048 | MEDIUM | 4.3 | 0.5% | Aug 31, 2022 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying... |
| CVE-2022-34383 | HIGH | 8.2 | 0.5% | Aug 31, 2022 | Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A loca... |
| CVE-2022-34373 | HIGH | 7.8 | 0.2% | Aug 31, 2022 | Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability... |
| CVE-2022-31233 | HIGH | 8 | 0.3% | Aug 31, 2022 | Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user... |
| CVE-2022-1841 | MEDIUM | 5.3 | 0.5% | Aug 31, 2022 | In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-boun... |
| CVE-2022-37128 | CRITICAL | 9.8 | 21.2% | Aug 31, 2022 | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. |
| CVE-2022-36046 | MEDIUM | 5.3 | 1.0% | Aug 31, 2022 | Next.js is a React framework that can provide building blocks to create web applications. All of the following must be t... |
| CVE-2022-38812 | MEDIUM | 6.5 | 2.1% | Aug 31, 2022 | AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |
| CVE-2022-38153 | MEDIUM | 5.9 | 1.7% | Aug 31, 2022 | An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is e... |
| CVE-2022-37184 | HIGH | 8.8 | 1.0% | Aug 31, 2022 | The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authe... |
| CVE-2022-37183 | MEDIUM | 6.1 | 0.6% | Aug 31, 2022 | Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now