2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27063MEDIUM6.1AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. Th...
CVE-2022-27062MEDIUM4.8AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulner...
CVE-2022-27061HIGH7.2AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Ad...
CVE-2022-26624MEDIUM6.1Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title paramete...
CVE-2022-1219HIGH7.5SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is ca...
CVE-2022-28805CRITICAL9.1singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, lea...
CVE-2022-28796HIGH7jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a tr...
CVE-2022-24681MEDIUM6.1Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock...
CVE-2022-26676CRITICAL9.8aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to uplo...
CVE-2022-26675HIGH7.5aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass aut...
CVE-2022-26671HIGH7.3Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated...
CVE-2022-26670HIGH8.8D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attack...
CVE-2022-26612CRITICAL9.8In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and ot...
CVE-2022-25597HIGH8.8ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unaut...
CVE-2022-25596HIGH8.8ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for...
CVE-2022-25595MEDIUM6.5ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of serv...
CVE-2022-25594MEDIUM5.3Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote att...
CVE-2022-23973HIGH8.8ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient val...
CVE-2022-23972HIGH8.8ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An u...
CVE-2022-23971HIGH8.1ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special charac...
CVE-2022-23970HIGH8.1ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special charac...
CVE-2022-22519HIGH7.5A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulti...
CVE-2022-22518MEDIUM6.5A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymou...
CVE-2022-22517HIGH7.5An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a v...
CVE-2022-22516HIGH7.8The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now