2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36688 | HIGH | 8.8 | 0.8% | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter... |
| CVE-2022-36687 | MEDIUM | 6.5 | 0.9% | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the comp... |
| CVE-2022-36686 | HIGH | 8.8 | 0.8% | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter... |
| CVE-2022-35020 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_c... |
| CVE-2022-35019 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a segmentation fault. |
| CVE-2022-35018 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a segmentation fault. |
| CVE-2022-35017 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a heap buffer overflow. |
| CVE-2022-35016 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a heap buffer overflow. |
| CVE-2022-35015 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h. |
| CVE-2022-35014 | MEDIUM | 5.5 | 0.4% | Aug 29, 2022 | Advancecomp v2.3 contains a segmentation fault. |
| CVE-2022-37059 | MEDIUM | 4.8 | 0.5% | Aug 29, 2022 | Cross Site Scripting (XSS) in Admin Panel of Subrion CMS 4.2.1 allows attacker to inject arbitrary code via Login Field |
| CVE-2022-3019 | HIGH | 8.8 | 0.7% | Aug 29, 2022 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that w... |
| CVE-2022-36194 | MEDIUM | 5.4 | 0.7% | Aug 29, 2022 | Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding ... |
| CVE-2022-32548 | CRITICAL | 9.8 | 33.8% | Aug 29, 2022 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin... |
| CVE-2022-22897 | CRITICAL | 9.8 | 10.2% | Aug 29, 2022 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder ... |
| CVE-2022-25921 | CRITICAL | 9.8 | 1.1% | Aug 29, 2022 | All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input pass... |
| CVE-2022-25644 | CRITICAL | 9.8 | 1.2% | Aug 29, 2022 | All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz... |
| CVE-2022-25641 | MEDIUM | 5.5 | 0.2% | Aug 29, 2022 | Foxit PDF Reader before 11.2.2 and PDF Editor before 11.2.2, and PhantomPDF before 10.1.8, mishandle cross-reference inf... |
| CVE-2022-21165 | CRITICAL | 9.8 | 3.0% | Aug 29, 2022 | All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu... |
| CVE-2022-34668 | CRITICAL | 9.8 | 8.2% | Aug 29, 2022 | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma... |
| CVE-2022-38511 | HIGH | 7.8 | 1.4% | Aug 29, 2022 | TOTOLINK A810R V5.9c.4050_B20190424 was discovered to contain a command injection vulnerability via the component downlo... |
| CVE-2022-38510 | HIGH | 7.8 | 0.3% | Aug 29, 2022 | Tenda_TX9pro V22.03.02.10 was discovered to contain a buffer overflow via the component httpd/SetNetControlList. |
| CVE-2022-36616 | HIGH | 7.8 | 0.3% | Aug 29, 2022 | TOTOLINK A810R V4.1.2cu.5182_B20201026 and V5.9c.4050_B20190424 was discovered to contain a hardcoded password for root ... |
| CVE-2022-36615 | HIGH | 7.8 | 0.3% | Aug 29, 2022 | TOTOLINK A3000RU V4.1.2cu.5185_B20201128 was discovered to contain a hardcoded password for root at /etc/shadow.sample. |
| CVE-2022-36614 | HIGH | 7.8 | 0.3% | Aug 29, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a hardcoded password for root at /etc/shadow.sample. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now