2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26290CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/Writ...
CVE-2022-26289CRITICAL9.8Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeC...
CVE-2022-25269MEDIUM6.1Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.
CVE-2022-25268HIGH8.8Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
CVE-2022-25267HIGH8.8Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).
CVE-2022-25266MEDIUM4.3Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).
CVE-2022-27254MEDIUM5.3The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows...
CVE-2022-27192HIGH7.5The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file downl...
CVE-2022-25041MEDIUM4.3OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
CVE-2022-24934CRITICAL9.8wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER i...
CVE-2022-24768HIGH8.8Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit...
CVE-2022-22819HIGH7.8NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM...
CVE-2022-24757HIGH7.5The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications....
CVE-2022-24731MEDIUM4.9Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before...
CVE-2022-24730MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before...
CVE-2022-23881CRITICAL9.8ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_te...
CVE-2022-23880CRITICAL9.8An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execu...
CVE-2022-25609MEDIUM5.4Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with c...
CVE-2022-25608MEDIUM5.4Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to tri...
CVE-2022-25223MEDIUM4.3Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=tra...
CVE-2022-25222CRITICAL9.8Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/...
CVE-2022-25221MEDIUM6.1Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a us...
CVE-2022-24293CRITICAL9.8Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut...
CVE-2022-24292CRITICAL9.8Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut...
CVE-2022-24291HIGH7.5Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execut...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now