2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-38880CRITICAL9.8The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party....
CVE-2022-2840CRITICAL9.8The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using th...
CVE-2022-2754CRITICAL9.8The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation paramet...
CVE-2022-40766CRITICAL9.8Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' subst...
CVE-2022-39217CRITICAL9.8some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security...
CVE-2022-40300CRITICAL9.8Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager P...
CVE-2022-37258CRITICAL9.8Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName ...
CVE-2022-35939CRITICAL9.8TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determ...
CVE-2022-35938CRITICAL9.1TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s...
CVE-2022-35937CRITICAL9.1TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s...
CVE-2022-3214CRITICAL9.8Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-c...
CVE-2022-38621CRITICAL9.8Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnera...
CVE-2022-39009CRITICAL9.8The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause ...
CVE-2022-39008CRITICAL9.1The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability m...
CVE-2022-39007CRITICAL9.8The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerabili...
CVE-2022-39003CRITICAL9.1Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the conf...
CVE-2022-39002CRITICAL9.8Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to ...
CVE-2022-39000CRITICAL9.8The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will caus...
CVE-2022-38999CRITICAL9.8The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability m...
CVE-2022-38831CRITICAL9.8Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList
CVE-2022-38830CRITICAL9.8Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.
CVE-2022-38829CRITICAL9.8Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.
CVE-2022-38828CRITICAL9.8TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi
CVE-2022-38827CRITICAL9.8TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi
CVE-2022-38826CRITICAL9.8In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now