2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38880 | CRITICAL | 9.8 | 1.0% | Sep 19, 2022 | The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party.... |
| CVE-2022-2840 | CRITICAL | 9.8 | 9.6% | Sep 19, 2022 | The Zephyr Project Manager WordPress plugin before 3.2.5 does not sanitise and escape various parameters before using th... |
| CVE-2022-2754 | CRITICAL | 9.8 | 37.7% | Sep 19, 2022 | The Ketchup Restaurant Reservations WordPress plugin through 1.0.0 does not validate and escape some reservation paramet... |
| CVE-2022-40766 | CRITICAL | 9.8 | 0.8% | Sep 18, 2022 | Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' subst... |
| CVE-2022-39217 | CRITICAL | 9.8 | 0.5% | Sep 17, 2022 | some-natalie/ghas-to-csv (GitHub Advanced Security to CSV) is a GitHub action which scrapes the GitHub Advanced Security... |
| CVE-2022-40300 | CRITICAL | 9.8 | 99.3% | Sep 16, 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager P... |
| CVE-2022-37258 | CRITICAL | 9.8 | 1.2% | Sep 16, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName ... |
| CVE-2022-35939 | CRITICAL | 9.8 | 0.4% | Sep 16, 2022 | TensorFlow is an open source platform for machine learning. The `ScatterNd` function takes an input argument that determ... |
| CVE-2022-35938 | CRITICAL | 9.1 | 0.4% | Sep 16, 2022 | TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s... |
| CVE-2022-35937 | CRITICAL | 9.1 | 0.4% | Sep 16, 2022 | TensorFlow is an open source platform for machine learning. The `GatherNd` function takes arguments that determine the s... |
| CVE-2022-3214 | CRITICAL | 9.8 | 1.4% | Sep 16, 2022 | Delta Industrial Automation's DIAEnergy, an industrial energy management system, is vulnerable to CWE-798, Use of Hard-c... |
| CVE-2022-38621 | CRITICAL | 9.8 | 24.1% | Sep 16, 2022 | Doufox v0.0.4 was discovered to contain a remote code execution (RCE) vulnerability via the edit file page. This vulnera... |
| CVE-2022-39009 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause ... |
| CVE-2022-39008 | CRITICAL | 9.1 | 0.5% | Sep 16, 2022 | The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability m... |
| CVE-2022-39007 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerabili... |
| CVE-2022-39003 | CRITICAL | 9.1 | 0.4% | Sep 16, 2022 | Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the conf... |
| CVE-2022-39002 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to ... |
| CVE-2022-39000 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will caus... |
| CVE-2022-38999 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability m... |
| CVE-2022-38831 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList |
| CVE-2022-38830 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status. |
| CVE-2022-38829 | CRITICAL | 9.8 | 1.0% | Sep 16, 2022 | Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg. |
| CVE-2022-38828 | CRITICAL | 9.8 | 19.3% | Sep 16, 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi |
| CVE-2022-38827 | CRITICAL | 9.8 | 12.0% | Sep 16, 2022 | TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi |
| CVE-2022-38826 | CRITICAL | 9.8 | 1.1% | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now