2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31879 | HIGH | 8.8 | 1.1% | Jul 26, 2022 | Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter. |
| CVE-2022-2225 | HIGH | 7.8 | 0.2% | Jul 26, 2022 | By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to b... |
| CVE-2022-33977 | HIGH | 7.5 | 1.4% | Jul 26, 2022 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr... |
| CVE-2022-31471 | HIGH | 7.5 | 1.3% | Jul 26, 2022 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr... |
| CVE-2022-30706 | MEDIUM | 6.1 | 0.5% | Jul 26, 2022 | Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user ... |
| CVE-2022-1042 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. |
| CVE-2022-1041 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. |
| CVE-2022-22686 | HIGH | 8 | 0.3% | Jul 26, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote... |
| CVE-2022-34749 | HIGH | 7.5 | 1.2% | Jul 25, 2022 | In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high a... |
| CVE-2022-34577 | CRITICAL | 9.8 | 1.7% | Jul 25, 2022 | A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a craf... |
| CVE-2022-34576 | HIGH | 7.5 | 2.9% | Jul 25, 2022 | A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arb... |
| CVE-2022-34575 | MEDIUM | 5.7 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info... |
| CVE-2022-34574 | MEDIUM | 5.7 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info... |
| CVE-2022-34573 | MEDIUM | 6.3 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configu... |
| CVE-2022-34572 | MEDIUM | 5.7 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet p... |
| CVE-2022-34571 | HIGH | 8 | 0.8% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the system k... |
| CVE-2022-34570 | HIGH | 7.5 | 0.8% | Jul 25, 2022 | WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the... |
| CVE-2022-35131 | CRITICAL | 9 | 2.1% | Jul 25, 2022 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. |
| CVE-2022-34907 | CRITICAL | 9.8 | 15.8% | Jul 25, 2022 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could all... |
| CVE-2022-34906 | HIGH | 7.5 | 10.5% | Jul 25, 2022 | A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an u... |
| CVE-2022-36375 | HIGH | 7.2 | 1.0% | Jul 25, 2022 | Authenticated (high role user) WordPress Options Change vulnerability in Biplob Adhikari's Tabs plugin <= 3.6.0 at WordP... |
| CVE-2022-35873 | HIGH | 7.8 | 0.6% | Jul 25, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I... |
| CVE-2022-35872 | HIGH | 7.8 | 0.6% | Jul 25, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I... |
| CVE-2022-35871 | HIGH | 7.8 | 39.2% | Jul 25, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I... |
| CVE-2022-35870 | HIGH | 7.8 | 43.1% | Jul 25, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation I... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now