2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38556CRITICAL9.8Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
CVE-2022-37057CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,...
CVE-2022-37053CRITICAL9.8TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
CVE-2022-36756CRITICAL9.8DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
CVE-2022-36755CRITICAL9.8D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request ...
CVE-2022-3017MEDIUM6.5Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 0.10.38.
CVE-2022-3016HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0286.
CVE-2022-38794HIGH7.5Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
CVE-2022-38792CRITICAL9.8The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
CVE-2022-38791MEDIUM5.5In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream w...
CVE-2022-2787MEDIUM4.3Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot s...
CVE-2022-3015MEDIUM6.1A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue ...
CVE-2022-3014MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability af...
CVE-2022-3013CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unk...
CVE-2022-3012HIGH8.8A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue ...
CVE-2022-36548MEDIUM5.4Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /pa...
CVE-2022-36547MEDIUM6.1Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at ...
CVE-2022-36546HIGH8.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/setting...
CVE-2022-36545CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p...
CVE-2022-36544CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p...
CVE-2022-36543CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p...
CVE-2022-36542MEDIUM6.5An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitra...
CVE-2022-2915HIGH8.8A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to c...
CVE-2022-36537HIGH7.5ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafte...
CVE-2022-38785Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2905. Reason: This candidate is a reservation du...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now