2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31649HIGH7.5ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.
CVE-2022-30075HIGH8.8In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote...
CVE-2022-25807MEDIUM5.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncry...
CVE-2022-25806HIGH8.8An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredenti...
CVE-2022-25805MEDIUM6.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind c...
CVE-2022-25804MEDIUM5.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig...
CVE-2022-24840CRITICAL9.8django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible t...
CVE-2022-31496HIGH8.8LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
CVE-2022-29014HIGH7.5A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary...
CVE-2022-29013CRITICAL9.8A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execut...
CVE-2022-31313CRITICAL9.8api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.
CVE-2022-30882CRITICAL9.8pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (re...
CVE-2022-30877CRITICAL9.8The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current v...
CVE-2022-30875MEDIUM6.1Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVE-2022-28386MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring...
CVE-2022-32273MEDIUM4.3As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allo...
CVE-2022-31325HIGH7.2There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.
CVE-2022-30899MEDIUM4.8A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
CVE-2022-28387MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked b...
CVE-2022-28385MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can ...
CVE-2022-28384MEDIUM5.5An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline ...
CVE-2022-28383MEDIUM6.8An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attac...
CVE-2022-28382HIGH7.5An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode...
CVE-2022-24296HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, A...
CVE-2022-30926CRITICAL9.8H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /g...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now