2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35521CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnable...
CVE-2022-35520CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden ...
CVE-2022-35519CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to ...
CVE-2022-35518CRITICAL9.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, whic...
CVE-2022-35517HIGH8.8WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wl...
CVE-2022-35509MEDIUM5.4An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute ar...
CVE-2022-35491CRITICAL9.8TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample.
CVE-2022-35426CRITICAL9.8UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
CVE-2022-35293CRITICAL9.1Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. ...
CVE-2022-35290HIGH7.5Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be...
CVE-2022-32429CRITICAL9.8An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog...
CVE-2022-32245HIGH8.2SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attack...
CVE-2022-32189HIGH7.5A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and ...
CVE-2022-32148MEDIUM6.5Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputi...
CVE-2022-31675HIGH7.5VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with netw...
CVE-2022-31674MEDIUM4.3VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo...
CVE-2022-31673HIGH8.8VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo...
CVE-2022-31672HIGH7.2VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network ...
CVE-2022-30635HIGH7.5Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a p...
CVE-2022-30633HIGH7.5Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic ...
CVE-2022-30632HIGH7.5Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due ...
CVE-2022-30631HIGH7.5Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a pan...
CVE-2022-30630HIGH7.5Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack...
CVE-2022-30629LOW3.1Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker ...
CVE-2022-30580HIGH7.8Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working d...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now