2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-36553CRITICAL9.8Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w...
CVE-2022-32993CRITICAL9.8TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.
CVE-2022-32548CRITICAL9.8An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin...
CVE-2022-22897CRITICAL9.8A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder ...
CVE-2022-25921CRITICAL9.8All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input pass...
CVE-2022-25644CRITICAL9.8All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz...
CVE-2022-21165CRITICAL9.8All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu...
CVE-2022-34668CRITICAL9.8NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma...
CVE-2022-36572CRITICAL9.8Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability v...
CVE-2022-36708CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/...
CVE-2022-36706CRITICAL9.8Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at...
CVE-2022-36705CRITICAL9.8Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at...
CVE-2022-38555CRITICAL9.8Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
CVE-2022-37056CRITICAL9.8D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin,...
CVE-2022-37055CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, h...
CVE-2022-38557CRITICAL9.8D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
CVE-2022-38556CRITICAL9.8Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.
CVE-2022-37057CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,...
CVE-2022-37053CRITICAL9.8TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
CVE-2022-36756CRITICAL9.8DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
CVE-2022-36755CRITICAL9.8D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request ...
CVE-2022-38792CRITICAL9.8The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
CVE-2022-3013CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unk...
CVE-2022-36545CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p...
CVE-2022-36544CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now