2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-1400CRITICAL9.8Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42...
CVE-2022-1399CRITICAL9.1An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery compo...
CVE-2022-37437CRITICAL9.8When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, T...
CVE-2022-34256CRITICAL9.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-2662CRITICAL9.8Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process...
CVE-2022-2847CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue ...
CVE-2022-36242CRITICAL9.8Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
CVE-2022-38193CRITICAL9.6There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, una...
CVE-2022-36599CRITICAL9.8Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CVE-2022-36273CRITICAL9.8Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.
CVE-2022-36272CRITICAL9.8Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName param...
CVE-2022-30264CRITICAL9.8The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize th...
CVE-2022-36344CRITICAL9.8An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple pro...
CVE-2022-36308CRITICAL9.1Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18....
CVE-2022-36010CRITICAL9.8This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https...
CVE-2022-35978CRITICAL10Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can se...
CVE-2022-36525CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticati...
CVE-2022-36523CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/up...
CVE-2022-36262CRITICAL9.8An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modify...
CVE-2022-34294CRITICAL9.8totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning becau...
CVE-2022-38221CRITICAL9.8A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 be...
CVE-2022-2812CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects u...
CVE-2022-2314CRITICAL9.8The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
CVE-2022-2180CRITICAL9.8The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any autho...
CVE-2022-35949CRITICAL9.8undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forge...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now