2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38556 | CRITICAL | 9.8 | 0.9% | Aug 28, 2022 | Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. |
| CVE-2022-37057 | CRITICAL | 9.8 | 25.1% | Aug 28, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,... |
| CVE-2022-37053 | CRITICAL | 9.8 | 2.6% | Aug 28, 2022 | TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php. |
| CVE-2022-36756 | CRITICAL | 9.8 | 3.0% | Aug 28, 2022 | DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php. |
| CVE-2022-36755 | CRITICAL | 9.8 | 1.1% | Aug 28, 2022 | D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request ... |
| CVE-2022-3017 | MEDIUM | 6.5 | 0.4% | Aug 28, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38. |
| CVE-2022-3016 | HIGH | 7.8 | 0.5% | Aug 28, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0286. |
| CVE-2022-38794 | HIGH | 7.5 | 3.4% | Aug 27, 2022 | Zaver through 2020-12-15 allows directory traversal via the GET /.. substring. |
| CVE-2022-38792 | CRITICAL | 9.8 | 1.1% | Aug 27, 2022 | The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party. |
| CVE-2022-38791 | MEDIUM | 5.5 | 0.2% | Aug 27, 2022 | In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream w... |
| CVE-2022-2787 | MEDIUM | 4.3 | 0.8% | Aug 27, 2022 | Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot s... |
| CVE-2022-3015 | MEDIUM | 6.1 | 0.3% | Aug 27, 2022 | A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue ... |
| CVE-2022-3014 | MEDIUM | 6.1 | 0.5% | Aug 27, 2022 | A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability af... |
| CVE-2022-3013 | CRITICAL | 9.8 | 0.4% | Aug 27, 2022 | A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unk... |
| CVE-2022-3012 | HIGH | 8.8 | 0.6% | Aug 27, 2022 | A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue ... |
| CVE-2022-36548 | MEDIUM | 5.4 | 0.5% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /pa... |
| CVE-2022-36547 | MEDIUM | 6.1 | 0.5% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at ... |
| CVE-2022-36546 | HIGH | 8.8 | 0.4% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/setting... |
| CVE-2022-36545 | CRITICAL | 9.8 | 1.0% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p... |
| CVE-2022-36544 | CRITICAL | 9.8 | 1.0% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p... |
| CVE-2022-36543 | CRITICAL | 9.8 | 1.0% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p... |
| CVE-2022-36542 | MEDIUM | 6.5 | 0.6% | Aug 26, 2022 | An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitra... |
| CVE-2022-2915 | HIGH | 8.8 | 1.3% | Aug 26, 2022 | A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to c... |
| CVE-2022-36537 | HIGH | 7.5 | 95.3% | Aug 26, 2022 | ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte... |
| CVE-2022-38785 | — | — | — | Aug 26, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2905. Reason: This candidate is a reservation du... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now