2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27134HIGH7.5EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which ...
CVE-2022-23742HIGH7.8Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a di...
CVE-2022-23166CRITICAL9.8Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/...
CVE-2022-23165MEDIUM6.1Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treec...
CVE-2022-23139HIGH8.8ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is...
CVE-2022-22971MEDIUM6.5In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS...
CVE-2022-22970MEDIUM5.3In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo...
CVE-2022-22798HIGH8.8Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker...
CVE-2022-22797MEDIUM6.1Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" reques...
CVE-2022-22796CRITICAL9.8Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, The...
CVE-2022-29369HIGH7.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.
CVE-2022-29368HIGH7.1Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the ...
CVE-2022-28819HIGH7.8Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vuln...
CVE-2022-28818MEDIUM6.1ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerab...
CVE-2022-29363CRITICAL9.8Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. T...
CVE-2022-27172HIGH8.8A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37...
CVE-2022-26782HIGH8.8Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ...
CVE-2022-26781HIGH8.8Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ...
CVE-2022-26780HIGH8.8Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ...
CVE-2022-26518HIGH8.8An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V...
CVE-2022-26510MEDIUM6.5A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37...
CVE-2022-26420HIGH8.8An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 ...
CVE-2022-26085HIGH8.8An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4...
CVE-2022-26075HIGH8.8An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 ...
CVE-2022-26042HIGH8.8An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now