2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29776CRITICAL9.8Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via ...
CVE-2022-29735HIGH8.8Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a craf...
CVE-2022-29734MEDIUM5.4A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrar...
CVE-2022-29733MEDIUM5.9Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive informatio...
CVE-2022-29732MEDIUM6.1Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vu...
CVE-2022-29731MEDIUM4.3An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.
CVE-2022-29730CRITICAL9.8USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest p...
CVE-2022-29729HIGH7.5Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which...
CVE-2022-29725HIGH8.8An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via ...
CVE-2022-29712CRITICAL9.8LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and ...
CVE-2022-29711MEDIUM6.1LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogCo...
CVE-2022-29695HIGH7.5Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization.
CVE-2022-29694HIGH7.5Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free.
CVE-2022-29693HIGH7.5Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc....
CVE-2022-29692HIGH7.8Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function.
CVE-2022-29659CRITICAL9.8Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
CVE-2022-29653MEDIUM6.1OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/...
CVE-2022-29648MEDIUM5.4A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM...
CVE-2022-29647HIGH8.8An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/...
CVE-2022-29628MEDIUM5.4A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute ...
CVE-2022-29627MEDIUM4.3An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are...
CVE-2022-29624HIGH8.8An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code...
CVE-2022-29598MEDIUM6.1Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulne...
CVE-2022-29540MEDIUM6.1resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject ar...
CVE-2022-29488HIGH7.8The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to ex...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now