2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25446CRITICAL9.8Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the schedstarttime parameter in the openSche...
CVE-2022-25445CRITICAL9.8Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the PowerSaveSet funct...
CVE-2022-25441CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the vlanid parameter ...
CVE-2022-25440CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the ntpserver parameter in the SetSysTimeCfg functi...
CVE-2022-25439CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetIpMacBind function.
CVE-2022-25438CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a remote command execution (RCE) vulnerability via the SetIPTVCfg functi...
CVE-2022-25437CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetVirtualServerCfg funct...
CVE-2022-25435CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the list parameter in the SetStaticRoutecfg functio...
CVE-2022-25434CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg func...
CVE-2022-25433CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the urls parameter in the saveparentcontrolinfo fun...
CVE-2022-25431CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain multiple stack overflows via the NPTR, V12, V10 and V11 parameter in the...
CVE-2022-25429CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a buffer overflow via the time parameter in the saveparentcontrolinfo fu...
CVE-2022-25428CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the deviceId parameter in the saveparentcontrolinfo...
CVE-2022-25427CRITICAL9.8Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the schedendtime parameter in the openSchedWifi fun...
CVE-2022-26502Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-27246MEDIUM6.1An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by defau...
CVE-2022-27245HIGH8.8An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI...
CVE-2022-27244MEDIUM4.8An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom ...
CVE-2022-27243HIGH7.8An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom term...
CVE-2022-25607HIGH7.2Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player W...
CVE-2022-25605MEDIUM5.4Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug...
CVE-2022-25604MEDIUM5.4Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress ...
CVE-2022-25603MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria Wor...
CVE-2022-25602HIGH8.8Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re...
CVE-2022-24092HIGH7.8Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now