2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35521 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnable... |
| CVE-2022-35520 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden ... |
| CVE-2022-35519 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to ... |
| CVE-2022-35518 | CRITICAL | 9.8 | 1.5% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, whic... |
| CVE-2022-35517 | HIGH | 8.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: web_pskValue, wl_Method, wl... |
| CVE-2022-35509 | MEDIUM | 5.4 | 0.5% | Aug 10, 2022 | An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute ar... |
| CVE-2022-35491 | CRITICAL | 9.8 | 0.7% | Aug 10, 2022 | TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample. |
| CVE-2022-35426 | CRITICAL | 9.8 | 0.9% | Aug 10, 2022 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. |
| CVE-2022-35293 | CRITICAL | 9.1 | 0.6% | Aug 10, 2022 | Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. ... |
| CVE-2022-35290 | HIGH | 7.5 | 0.7% | Aug 10, 2022 | Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be... |
| CVE-2022-32429 | CRITICAL | 9.8 | 75.7% | Aug 10, 2022 | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog... |
| CVE-2022-32245 | HIGH | 8.2 | 0.4% | Aug 10, 2022 | SAP BusinessObjects Business Intelligence Platform (Open Document) - versions 420, 430, allows an unauthenticated attack... |
| CVE-2022-32189 | HIGH | 7.5 | 2.0% | Aug 10, 2022 | A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and ... |
| CVE-2022-32148 | MEDIUM | 6.5 | 1.1% | Aug 10, 2022 | Improper exposure of client IP addresses in net/http before Go 1.17.12 and Go 1.18.4 can be triggered by calling httputi... |
| CVE-2022-31675 | HIGH | 7.5 | 0.7% | Aug 10, 2022 | VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with netw... |
| CVE-2022-31674 | MEDIUM | 4.3 | 0.5% | Aug 10, 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo... |
| CVE-2022-31673 | HIGH | 8.8 | 1.3% | Aug 10, 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo... |
| CVE-2022-31672 | HIGH | 7.2 | 0.6% | Aug 10, 2022 | VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network ... |
| CVE-2022-30635 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | Uncontrolled recursion in Decoder.Decode in encoding/gob before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a p... |
| CVE-2022-30633 | HIGH | 7.5 | 1.6% | Aug 10, 2022 | Uncontrolled recursion in Unmarshal in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic ... |
| CVE-2022-30632 | HIGH | 7.5 | 1.6% | Aug 10, 2022 | Uncontrolled recursion in Glob in path/filepath before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due ... |
| CVE-2022-30631 | HIGH | 7.5 | 1.6% | Aug 10, 2022 | Uncontrolled recursion in Reader.Read in compress/gzip before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a pan... |
| CVE-2022-30630 | HIGH | 7.5 | 1.6% | Aug 10, 2022 | Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack... |
| CVE-2022-30629 | LOW | 3.1 | 0.9% | Aug 10, 2022 | Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker ... |
| CVE-2022-30580 | HIGH | 7.8 | 0.6% | Aug 10, 2022 | Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working d... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now