2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36599CRITICAL9.8Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CVE-2022-36530MEDIUM6.1An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the i...
CVE-2022-36273CRITICAL9.8Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.
CVE-2022-36272CRITICAL9.8Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName param...
CVE-2022-30264CRITICAL9.8The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize th...
CVE-2022-29959MEDIUM5.5Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave a...
CVE-2022-2838MEDIUM5.3In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced e...
CVE-2022-36381HIGH7.2OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an adm...
CVE-2022-36344CRITICAL9.8An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple pro...
CVE-2022-36293HIGH7.2Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administ...
CVE-2022-35734HIGH7.5'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an externa...
CVE-2022-35239HIGH8.8The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and ea...
CVE-2022-34156MEDIUM4.8'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker ...
CVE-2022-33939HIGH7.5CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication p...
CVE-2022-38216HIGH7.5An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with mu...
CVE-2022-36312HIGH8.8Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This i...
CVE-2022-36311MEDIUM6.1Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP c...
CVE-2022-36310HIGH8.8Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, e...
CVE-2022-36309HIGH8.8Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the Act...
CVE-2022-36308CRITICAL9.1Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18....
CVE-2022-36307MEDIUM6.8The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in Air...
CVE-2022-36306MEDIUM6.5An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS pri...
CVE-2022-24952MEDIUM6.5Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered re...
CVE-2022-24951HIGH7A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Termi...
CVE-2022-24950HIGH7.5A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now