2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31879HIGH8.8Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
CVE-2022-2225HIGH7.8By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to b...
CVE-2022-33977HIGH7.5untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr...
CVE-2022-31471HIGH7.5untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr...
CVE-2022-30706MEDIUM6.1Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user ...
CVE-2022-1042HIGH8.8In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
CVE-2022-1041HIGH8.8In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning.
CVE-2022-22686HIGH8Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote...
CVE-2022-34749HIGH7.5In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high a...
CVE-2022-34577CRITICAL9.8A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a craf...
CVE-2022-34576HIGH7.5A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arb...
CVE-2022-34575MEDIUM5.7An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info...
CVE-2022-34574MEDIUM5.7An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info...
CVE-2022-34573MEDIUM6.3An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configu...
CVE-2022-34572MEDIUM5.7An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet p...
CVE-2022-34571HIGH8An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system k...
CVE-2022-34570HIGH7.5WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the...
CVE-2022-35131CRITICAL9Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVE-2022-34907CRITICAL9.8An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could all...
CVE-2022-34906HIGH7.5A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an u...
CVE-2022-36375HIGH7.2Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordP...
CVE-2022-35873HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I...
CVE-2022-35872HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I...
CVE-2022-35871HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I...
CVE-2022-35870HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now