2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28909 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx param... |
| CVE-2022-28908 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin paramet... |
| CVE-2022-28907 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime functio... |
| CVE-2022-28906 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype paramet... |
| CVE-2022-28905 | CRITICAL | 9.8 | 2.5% | May 10, 2022 | TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parame... |
| CVE-2022-28901 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows a... |
| CVE-2022-28896 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 all... |
| CVE-2022-28895 | CRITICAL | 9.8 | 3.6% | May 10, 2022 | A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allo... |
| CVE-2022-1629 | HIGH | 7.8 | 1.8% | May 10, 2022 | Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are ca... |
| CVE-2022-1621 | HIGH | 7.8 | 2.3% | May 10, 2022 | Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capa... |
| CVE-2022-1537 | HIGH | 7 | 0.3% | May 10, 2022 | file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repo... |
| CVE-2022-1397 | HIGH | 8.8 | 1.1% | May 10, 2022 | API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover. |
| CVE-2022-29591 | CRITICAL | 9.8 | 1.3% | May 10, 2022 | Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow. |
| CVE-2022-28110 | CRITICAL | 9.8 | 0.9% | May 10, 2022 | Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the l... |
| CVE-2022-24042 | CRITICAL | 9.1 | 0.9% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-24041 | MEDIUM | 6.5 | 0.4% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-24040 | MEDIUM | 6.5 | 0.8% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-24039 | CRITICAL | 9 | 1.8% | May 10, 2022 | A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02... |
| CVE-2022-23705 | HIGH | 7.5 | 1.0% | May 9, 2022 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr... |
| CVE-2022-23704 | HIGH | 7.5 | 1.8% | May 9, 2022 | A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow... |
| CVE-2022-30335 | CRITICAL | 9.8 | 1.1% | May 9, 2022 | Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application w... |
| CVE-2022-29868 | MEDIUM | 5.5 | 0.2% | May 9, 2022 | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software runn... |
| CVE-2022-30524 | HIGH | 7.8 | 1.6% | May 9, 2022 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mis... |
| CVE-2022-30240 | HIGH | 7.8 | 0.5% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift... |
| CVE-2022-30239 | HIGH | 7.8 | 0.5% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena J... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now