2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1080CRITICAL9.8A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vul...
CVE-2022-1079MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester One Church Management System. Affected are mu...
CVE-2022-1078CRITICAL9.8A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. A...
CVE-2022-1077HIGH7.5A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability ...
CVE-2022-1076MEDIUM6.1A vulnerability was found in Automatic Question Paper Generator System 1.0. It has been classified as problematic. This ...
CVE-2022-1075MEDIUM5.4A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue...
CVE-2022-1074MEDIUM5.4A vulnerability has been found in TEM FLEX-1085 1.6.0 and classified as problematic. Using the input <h1>HTML Injection<...
CVE-2022-1073CRITICAL9.8A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads t...
CVE-2022-1072Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26254. Reason: This candidate is a reservation d...
CVE-2022-25420CRITICAL9.8NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows at...
CVE-2022-24957MEDIUM5.4DHC Vision eQMS through 5.4.8.322 has Persistent XSS due to insufficient encoding of untrusted input/output. To exploit ...
CVE-2022-24956MEDIUM6.5An issue was discovered in Shopware B2B-Suite through 4.4.1. The sort-by parameter of the search functionality of b2bord...
CVE-2022-23937HIGH7.5In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial excha...
CVE-2022-26269MEDIUM4.6Suzuki Connect v1.0.15 allows attackers to tamper with displayed messages via spoofed CAN messages.
CVE-2022-25521CRITICAL9.8NUUO v03.11.00 was discovered to contain access control issue.
CVE-2022-0331MEDIUM5.3An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial ...
CVE-2022-26642HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
CVE-2022-26641HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
CVE-2022-26640HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
CVE-2022-26639HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
CVE-2022-26296MEDIUM5.5BOOM: The Berkeley Out-of-Order RISC-V Processor commit d77c2c3 was discovered to allow unauthorized disclosure of infor...
CVE-2022-26291MEDIUM5.5lrzip v0.641 was discovered to contain a multiple concurrency use-after-free between the functions zpaq_decompress_buf()...
CVE-2022-26280MEDIUM6.5Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
CVE-2022-24789HIGH7.6C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user...
CVE-2022-26278CRITICAL9.8Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now