2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35899HIGH7.8There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local...
CVE-2022-30337MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacke...
CVE-2022-28666MEDIUM5.3Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leadi...
CVE-2022-36313MEDIUM5.5An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file ...
CVE-2022-34767CRITICAL9.8Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the passwor...
CVE-2022-32430HIGH7.5An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions w...
CVE-2022-32289MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup s...
CVE-2022-30628MEDIUM5.5It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/se...
CVE-2022-28877MEDIUM6.7This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can ...
CVE-2022-28861MEDIUM5.9The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Ax...
CVE-2022-28860MEDIUM5.9An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the...
CVE-2022-0902CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Eleme...
CVE-2022-20890HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20889HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20888HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20887HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20886HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20885HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-32556HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
CVE-2022-20884HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20883HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20882HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20881HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-34367HIGH8.8Dell EMC Data Protection Central versions 19.1, 19.2, 19.3, 19.4, 19.5, 19.6, contain(s) a Cross-Site Request Forgery Vu...
CVE-2022-33923HIGH7.8Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now