2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26189CRITICAL9.8TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType para...
CVE-2022-26188CRITICAL9.8TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncW...
CVE-2022-26187CRITICAL9.8TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck fun...
CVE-2022-26186CRITICAL9.8TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn in...
CVE-2022-1031HIGH7.8Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.
CVE-2022-26260CRITICAL9.8Simple-Plist v1.3.0 was discovered to contain a prototype pollution vulnerability via .parse().
CVE-2022-25517CRITICAL9.8MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions...
CVE-2022-27228CRITICAL9.8In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can ex...
CVE-2022-25484MEDIUM5.5tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
CVE-2022-24774HIGH8.1CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneD...
CVE-2022-24764HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack b...
CVE-2022-21718MEDIUM5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability ...
CVE-2022-1036HIGH7.5Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweb...
CVE-2022-0667HIGH7.5When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
CVE-2022-1034HIGH7.2There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2....
CVE-2022-0652HIGH7.8Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. Th...
CVE-2022-0386HIGH8.8A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code...
CVE-2022-27607HIGH8.1Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.
CVE-2022-26285CRITICAL9.8Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the app...
CVE-2022-26284CRITICAL9.8Simple Client Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the...
CVE-2022-26283CRITICAL9.8Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the vie...
CVE-2022-27333HIGH7.5idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resu...
CVE-2022-27090MEDIUM5.4Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
CVE-2022-26184CRITICAL9.8Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in une...
CVE-2022-26183HIGH8.8PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unex...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now