2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25446 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSche... |
| CVE-2022-25445 | CRITICAL | 9.8 | 9.0% | Mar 18, 2022 | Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet funct... |
| CVE-2022-25441 | CRITICAL | 9.8 | 4.6% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter ... |
| CVE-2022-25440 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg functi... |
| CVE-2022-25439 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function. |
| CVE-2022-25438 | CRITICAL | 9.8 | 4.6% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg functi... |
| CVE-2022-25437 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg funct... |
| CVE-2022-25435 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg functio... |
| CVE-2022-25434 | CRITICAL | 9.8 | 9.1% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg func... |
| CVE-2022-25433 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo fun... |
| CVE-2022-25431 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the... |
| CVE-2022-25429 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo fu... |
| CVE-2022-25428 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo... |
| CVE-2022-25427 | CRITICAL | 9.8 | 1.7% | Mar 18, 2022 | Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi fun... |
| CVE-2022-26502 | — | — | — | Mar 18, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-27246 | MEDIUM | 6.1 | 0.6% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by defau... |
| CVE-2022-27245 | HIGH | 8.8 | 0.9% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI... |
| CVE-2022-27244 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom ... |
| CVE-2022-27243 | HIGH | 7.8 | 1.2% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom term... |
| CVE-2022-25607 | HIGH | 7.2 | 0.8% | Mar 18, 2022 | Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player W... |
| CVE-2022-25605 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug... |
| CVE-2022-25604 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress ... |
| CVE-2022-25603 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria Wor... |
| CVE-2022-25602 | HIGH | 8.8 | 1.3% | Mar 18, 2022 | Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re... |
| CVE-2022-24092 | HIGH | 7.8 | 4.2% | Mar 18, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now