2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28909CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx param...
CVE-2022-28908CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin paramet...
CVE-2022-28907CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime functio...
CVE-2022-28906CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet...
CVE-2022-28905CRITICAL9.8TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parame...
CVE-2022-28901CRITICAL9.8A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows a...
CVE-2022-28896CRITICAL9.8A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 all...
CVE-2022-28895CRITICAL9.8A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allo...
CVE-2022-1629HIGH7.8Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are ca...
CVE-2022-1621HIGH7.8Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capa...
CVE-2022-1537HIGH7file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repo...
CVE-2022-1397HIGH8.8API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.
CVE-2022-29591CRITICAL9.8Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.
CVE-2022-28110CRITICAL9.8Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the l...
CVE-2022-24042CRITICAL9.1A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21....
CVE-2022-24041MEDIUM6.5A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21....
CVE-2022-24040MEDIUM6.5A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21....
CVE-2022-24039CRITICAL9A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02...
CVE-2022-23705HIGH7.5A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr...
CVE-2022-23704HIGH7.5A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow...
CVE-2022-30335CRITICAL9.8Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application w...
CVE-2022-29868MEDIUM5.51Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software runn...
CVE-2022-30524HIGH7.8There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mis...
CVE-2022-30240HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift...
CVE-2022-30239HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena J...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now