2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29166HIGH8.8matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate...
CVE-2022-29176HIGH7.5Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,...
CVE-2022-27411CRITICAL9.8TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING par...
CVE-2022-27360CRITICAL9.8SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2022-27359MEDIUM5.5Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.
CVE-2022-27337MEDIUM6.5A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a...
CVE-2022-28584CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu...
CVE-2022-28583CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2...
CVE-2022-28582CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28581CRITICAL9.8It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7....
CVE-2022-28580CRITICAL9.8It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28579CRITICAL9.8It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28578CRITICAL9.8It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2...
CVE-2022-28577CRITICAL9.8It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4c...
CVE-2022-28575CRITICAL9.8It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7...
CVE-2022-26073MEDIUM6.5A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1....
CVE-2022-25989HIGH8.8An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1...
CVE-2022-29592CRITICAL9.8Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).
CVE-2022-29502CRITICAL9.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
CVE-2022-29501HIGH8.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execu...
CVE-2022-29500HIGH8.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
CVE-2022-29491HIGH7.5On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x v...
CVE-2022-29480MEDIUM5.3On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are con...
CVE-2022-29479MEDIUM5.3On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and ...
CVE-2022-29474MEDIUM4.3On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now