2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22515HIGH8.1A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vuln...
CVE-2022-22514HIGH7.1An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can sub...
CVE-2022-22513MEDIUM6.5An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODES...
CVE-2022-0935HIGH8.8Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
CVE-2022-0677HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint...
CVE-2022-27022CRITICAL9.8There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn...
CVE-2022-27016CRITICAL9.8There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21...
CVE-2022-26627HIGH8.8Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows ...
CVE-2022-25339MEDIUM5.5ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
CVE-2022-25338MEDIUM6.8ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
CVE-2022-23900CRITICAL9.8A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an att...
CVE-2022-27819MEDIUM5.3SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of ser...
CVE-2022-27818CRITICAL9.1SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.
CVE-2022-26613CRITICAL9.8PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php.
CVE-2022-26607HIGH7.2A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbit...
CVE-2022-26605HIGH8.8eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality.
CVE-2022-26591HIGH7.5FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a ...
CVE-2022-20782MEDIUM6.5A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2022-20781MEDIUM5.4A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) c...
CVE-2022-20774HIGH8.1A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform F...
CVE-2022-20763HIGH8.8A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attac...
CVE-2022-20762HIGH7.8A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices...
CVE-2022-20756HIGH7.5A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att...
CVE-2022-20755HIGH7.2Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc...
CVE-2022-20754HIGH7.2Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now