2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1011HIGH7.8A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allo...
CVE-2022-1003MEDIUM4.9One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste...
CVE-2022-1002MEDIUM5.4Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh...
CVE-2022-0547CRITICAL9.8OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than...
CVE-2022-24637CRITICAL9.8Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh...
CVE-2022-24773MEDIUM5.3Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2022-24772HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2022-24771HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2022-24595CRITICAL9.8Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Cont...
CVE-2022-0742HIGH7.5Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-...
CVE-2022-24655HIGH7.8A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0...
CVE-2022-27191HIGH7.5The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server...
CVE-2022-26965HIGH7.2In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot...
CVE-2022-27240CRITICAL9.8scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion.
CVE-2022-0758MEDIUM6.1Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the share...
CVE-2022-0757HIGH8.8Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search opera...
CVE-2022-0237HIGH7.8Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker...
CVE-2022-24302MEDIUM5.9In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could al...
CVE-2022-26504HIGH8.8Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Cen...
CVE-2022-26501CRITICAL9.8Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
CVE-2022-26500HIGH8.8Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated ...
CVE-2022-24770HIGH8.8`gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11...
CVE-2022-21822HIGH7.5NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Re...
CVE-2022-26511HIGH7.8WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
CVE-2022-26081HIGH7.8The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary co...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now