2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36553 | CRITICAL | 9.8 | 90.8% | Aug 29, 2022 | Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /w... |
| CVE-2022-32993 | CRITICAL | 9.8 | 0.8% | Aug 29, 2022 | TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh. |
| CVE-2022-32548 | CRITICAL | 9.8 | 33.8% | Aug 29, 2022 | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin... |
| CVE-2022-22897 | CRITICAL | 9.8 | 10.2% | Aug 29, 2022 | A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder ... |
| CVE-2022-25921 | CRITICAL | 9.8 | 1.1% | Aug 29, 2022 | All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input pass... |
| CVE-2022-25644 | CRITICAL | 9.8 | 1.2% | Aug 29, 2022 | All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitiz... |
| CVE-2022-21165 | CRITICAL | 9.8 | 3.0% | Aug 29, 2022 | All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of inpu... |
| CVE-2022-34668 | CRITICAL | 9.8 | 8.2% | Aug 29, 2022 | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage ma... |
| CVE-2022-36572 | CRITICAL | 9.8 | 21.1% | Aug 29, 2022 | Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability v... |
| CVE-2022-36708 | CRITICAL | 9.8 | 0.9% | Aug 28, 2022 | Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/... |
| CVE-2022-36706 | CRITICAL | 9.8 | 0.9% | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at... |
| CVE-2022-36705 | CRITICAL | 9.8 | 0.9% | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at... |
| CVE-2022-38555 | CRITICAL | 9.8 | 12.2% | Aug 28, 2022 | Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name. |
| CVE-2022-37056 | CRITICAL | 9.8 | 10.2% | Aug 28, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin,... |
| CVE-2022-37055 | CRITICAL | 9.8 | 57.0% | Aug 28, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, h... |
| CVE-2022-38557 | CRITICAL | 9.8 | 0.8% | Aug 28, 2022 | D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. |
| CVE-2022-38556 | CRITICAL | 9.8 | 0.9% | Aug 28, 2022 | Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh. |
| CVE-2022-37057 | CRITICAL | 9.8 | 25.1% | Aug 28, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin,... |
| CVE-2022-37053 | CRITICAL | 9.8 | 2.6% | Aug 28, 2022 | TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php. |
| CVE-2022-36756 | CRITICAL | 9.8 | 3.0% | Aug 28, 2022 | DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php. |
| CVE-2022-36755 | CRITICAL | 9.8 | 1.1% | Aug 28, 2022 | D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request ... |
| CVE-2022-38792 | CRITICAL | 9.8 | 1.1% | Aug 27, 2022 | The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party. |
| CVE-2022-3013 | CRITICAL | 9.8 | 0.4% | Aug 27, 2022 | A vulnerability classified as critical has been found in SourceCodester Simple Task Managing System. This affects an unk... |
| CVE-2022-36545 | CRITICAL | 9.8 | 1.0% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p... |
| CVE-2022-36544 | CRITICAL | 9.8 | 1.0% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now