2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38823 | CRITICAL | 9.8 | 0.9% | Sep 16, 2022 | In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample. |
| CVE-2022-25708 | CRITICAL | 9.8 | 0.4% | Sep 16, 2022 | Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivit... |
| CVE-2022-25688 | CRITICAL | 9.8 | 0.3% | Sep 16, 2022 | Memory corruption in video due to buffer overflow while parsing ps video clips in Snapdragon Auto, Snapdragon Compute, S... |
| CVE-2022-25686 | CRITICAL | 9.8 | 0.3% | Sep 16, 2022 | Memory corruption in video module due to buffer overflow while processing WAV file in Snapdragon Auto, Snapdragon Comput... |
| CVE-2022-22105 | CRITICAL | 9.8 | 0.4% | Sep 16, 2022 | Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon ... |
| CVE-2022-36536 | CRITICAL | 9.8 | 5.2% | Sep 16, 2022 | An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be... |
| CVE-2022-26959 | CRITICAL | 9.8 | 0.8% | Sep 16, 2022 | There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version ... |
| CVE-2022-38326 | CRITICAL | 9.8 | 0.9% | Sep 15, 2022 | Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov... |
| CVE-2022-38325 | CRITICAL | 9.8 | 0.9% | Sep 15, 2022 | Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov... |
| CVE-2022-37861 | CRITICAL | 9.8 | 1.8% | Sep 15, 2022 | There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary ... |
| CVE-2022-37264 | CRITICAL | 9.8 | 1.1% | Sep 15, 2022 | Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js. |
| CVE-2022-2471 | CRITICAL | 9.8 | 1.2% | Sep 15, 2022 | Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-... |
| CVE-2022-37266 | CRITICAL | 9.8 | 1.0% | Sep 15, 2022 | Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js... |
| CVE-2022-37257 | CRITICAL | 9.8 | 1.1% | Sep 15, 2022 | Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVer... |
| CVE-2022-38789 | CRITICAL | 9.1 | 0.9% | Sep 15, 2022 | An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and ... |
| CVE-2022-38352 | CRITICAL | 9.8 | 20.2% | Sep 15, 2022 | ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Sto... |
| CVE-2022-38308 | CRITICAL | 9.8 | 20.3% | Sep 14, 2022 | TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter... |
| CVE-2022-35947 | CRITICAL | 9.8 | 0.9% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-37661 | CRITICAL | 9.8 | 36.2% | Sep 14, 2022 | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. |
| CVE-2022-37138 | CRITICAL | 9.8 | 1.0% | Sep 14, 2022 | Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as... |
| CVE-2022-36669 | CRITICAL | 9.8 | 2.1% | Sep 14, 2022 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication... |
| CVE-2022-36436 | CRITICAL | 9.8 | 1.7% | Sep 14, 2022 | OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentica... |
| CVE-2022-2900 | CRITICAL | 9.1 | 0.9% | Sep 14, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0. |
| CVE-2022-34831 | CRITICAL | 9.8 | 0.4% | Sep 14, 2022 | An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers... |
| CVE-2022-38771 | CRITICAL | 9.8 | 1.0% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tag... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now