2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1110MEDIUM5.5A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to...
CVE-2022-30065HIGH7.8A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a...
CVE-2022-29518HIGH7Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 vers...
CVE-2022-29516CRITICAL9.8The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(...
CVE-2022-28717MEDIUM4.8Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT l...
CVE-2022-27632HIGH8.8Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions,...
CVE-2022-1795CRITICAL9.8Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV.
CVE-2022-1782MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11.
CVE-2022-23068MEDIUM5.4ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside t...
CVE-2022-23067HIGH8.8ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If...
CVE-2022-1727HIGH8.8Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.
CVE-2022-1432MEDIUM6.4Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-1430HIGH7.5Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-29646MEDIUM5.3An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtai...
CVE-2022-29645CRITICAL9.8TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for...
CVE-2022-29644CRITICAL9.8TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for...
CVE-2022-29643HIGH7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ...
CVE-2022-29642HIGH7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ...
CVE-2022-29641HIGH7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ...
CVE-2022-29640HIGH7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ...
CVE-2022-29639HIGH8.1TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulne...
CVE-2022-29638HIGH7.5TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ...
CVE-2022-28958Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2022-28956CRITICAL9.8An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payl...
CVE-2022-28955HIGH7.5An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php an...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now