2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-4037HIGH8.5An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor...
CVE-2022-3613HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor...
CVE-2022-4874HIGH7.5Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access conte...
CVE-2022-4499HIGH7.5TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials i...
CVE-2022-4428HIGH8support_uri parameter in the WARP client local settings file (mdm.xml) lacked proper validation which allowed for privil...
CVE-2022-4696HIGH7.8There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If ...
CVE-2022-42271HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-43393HIGH8.2An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 fir...
CVE-2022-43390HIGH8.8A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allo...
CVE-2022-4379HIGH7.5A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allow...
CVE-2022-46449HIGH7.5An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2022-46163HIGH7.5Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank...
CVE-2022-45165HIGH8.8An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-cont...
CVE-2022-38492HIGH8.8An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022....
CVE-2022-38491HIGH7.5An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protec...
CVE-2022-38490HIGH8.8An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022...
CVE-2022-38393HIGH7.5A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386...
CVE-2022-38105HIGH7.5An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge18223...
CVE-2022-36443HIGH7.8An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The device allows the administrator to lock some communi...
CVE-2022-36441HIGH7.1An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to...
CVE-2022-35401HIGH8.1An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_4967...
CVE-2022-4636HIGH7.5Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T ...
CVE-2022-4704HIGH8.1The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_template...
CVE-2022-4703HIGH8.1The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_...
CVE-2022-4701HIGH8.8The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_requir...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now