2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35525 | CRITICAL | 9.8 | 2.4% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to co... |
| CVE-2022-35524 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, ... |
| CVE-2022-35523 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter del_mac and parameter fl... |
| CVE-2022-35522 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: ppp_username, ppp_passwd, r... |
| CVE-2022-35521 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameters: remoteManagementEnable... |
| CVE-2022-35520 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 api.cgi has no filtering on parameter ufconf, and this is a hidden ... |
| CVE-2022-35519 | CRITICAL | 9.8 | 2.3% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter add_mac, which leads to ... |
| CVE-2022-35518 | CRITICAL | 9.8 | 1.5% | Aug 10, 2022 | WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 nas.cgi has no filtering on parameters: User1Passwd and User1, whic... |
| CVE-2022-35491 | CRITICAL | 9.8 | 0.7% | Aug 10, 2022 | TOTOLINK A3002RU V3.0.0-B20220304.1804 has a hardcoded password for root in /etc/shadow.sample. |
| CVE-2022-35426 | CRITICAL | 9.8 | 0.9% | Aug 10, 2022 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. |
| CVE-2022-35293 | CRITICAL | 9.1 | 0.6% | Aug 10, 2022 | Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. ... |
| CVE-2022-32429 | CRITICAL | 9.8 | 75.7% | Aug 10, 2022 | An authentication-bypass issue in the component http://MYDEVICEIP/cgi-bin-sdb/ExportSettings.sh of Mega System Technolog... |
| CVE-2022-2634 | CRITICAL | 9.8 | 0.8% | Aug 10, 2022 | An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions... |
| CVE-2022-2457 | CRITICAL | 9.8 | 0.5% | Aug 10, 2022 | A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against... |
| CVE-2022-20361 | CRITICAL | 9.8 | 0.9% | Aug 10, 2022 | In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakn... |
| CVE-2022-20239 | CRITICAL | 9.8 | 0.2% | Aug 10, 2022 | remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm... |
| CVE-2022-35280 | CRITICAL | 9.8 | 0.7% | Aug 10, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by de... |
| CVE-2022-36323 | CRITICAL | 9.1 | 1.3% | Aug 10, 2022 | Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with admini... |
| CVE-2022-34660 | CRITICAL | 9.8 | 1.1% | Aug 10, 2022 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V1... |
| CVE-2022-2242 | CRITICAL | 9.8 | 0.9% | Aug 10, 2022 | The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker... |
| CVE-2022-20842 | CRITICAL | 9.8 | 1.6% | Aug 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti... |
| CVE-2022-20827 | CRITICAL | 10 | 1.7% | Aug 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti... |
| CVE-2022-20841 | CRITICAL | 9 | 2.9% | Aug 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenti... |
| CVE-2022-34715 | CRITICAL | 9.8 | 80.1% | Aug 9, 2022 | Windows Network File System Remote Code Execution Vulnerability |
| CVE-2022-33649 | CRITICAL | 9.6 | 1.9% | Aug 9, 2022 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now