2022 CVE Vulnerabilities

27,540 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37024HIGH8.8Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils...
CVE-2022-37008HIGH7.5The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploi...
CVE-2022-37007HIGH7.5The chinadrm module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may affect th...
CVE-2022-37006HIGH7.5Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service...
CVE-2022-37005HIGH7.5The Settings application has an argument injection vulnerability. Successful exploitation of this vulnerability may affe...
CVE-2022-37004HIGH7.5The Settings application has a vulnerability of bypassing the out-of-box experience (OOBE). Successful exploitation of t...
CVE-2022-37003CRITICAL9.8The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause per...
CVE-2022-37002CRITICAL9.8The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause ma...
CVE-2022-37001HIGH7.5The diag-router module has a vulnerability in intercepting excessive long and short instructions. Successful exploitatio...
CVE-2022-36923HIGH7.5Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall An...
CVE-2022-36750CRITICAL9.8Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
CVE-2022-36270CRITICAL9.8Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
CVE-2022-35697MEDIUM5.4Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (X...
CVE-2022-35538CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al...
CVE-2022-35537CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, wh...
CVE-2022-35536CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, w...
CVE-2022-35535CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to ...
CVE-2022-35534CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G...
CVE-2022-35533CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: cli_list and cli_num, which...
CVE-2022-35526CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command...
CVE-2022-35525CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to co...
CVE-2022-35524CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, ...
CVE-2022-35523CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter del_mac and parameter fl...
CVE-2022-35522CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, r...
CVE-2022-35521CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnable...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now