2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36688HIGH8.8Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter...
CVE-2022-36687MEDIUM6.5Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the comp...
CVE-2022-36686HIGH8.8Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter...
CVE-2022-35020MEDIUM5.5Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_c...
CVE-2022-35019MEDIUM5.5Advancecomp v2.3 was discovered to contain a segmentation fault.
CVE-2022-35018MEDIUM5.5Advancecomp v2.3 was discovered to contain a segmentation fault.
CVE-2022-35017MEDIUM5.5Advancecomp v2.3 was discovered to contain a heap buffer overflow.
CVE-2022-35016MEDIUM5.5Advancecomp v2.3 was discovered to contain a heap buffer overflow.
CVE-2022-35015MEDIUM5.5Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.
CVE-2022-35014MEDIUM5.5Advancecomp v2.3 contains a segmentation fault.
CVE-2022-37059MEDIUM4.8Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field
CVE-2022-3019HIGH8.8The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that w...
CVE-2022-36194MEDIUM5.4Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding ...
CVE-2022-32548CRITICAL9.8An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin...
CVE-2022-22897CRITICAL9.8A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder ...
CVE-2022-25921CRITICAL9.8All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input pass...
CVE-2022-25644CRITICAL9.8All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz...
CVE-2022-25641MEDIUM5.5Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference inf...
CVE-2022-21165CRITICAL9.8All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu...
CVE-2022-34668CRITICAL9.8NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma...
CVE-2022-38511HIGH7.8TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downlo...
CVE-2022-38510HIGH7.8Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList.
CVE-2022-36616HIGH7.8TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root ...
CVE-2022-36615HIGH7.8TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2022-36614HIGH7.8TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now