2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1011 | HIGH | 7.8 | 1.2% | Mar 18, 2022 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allo... |
| CVE-2022-1003 | MEDIUM | 4.9 | 0.5% | Mar 18, 2022 | One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste... |
| CVE-2022-1002 | MEDIUM | 5.4 | 0.6% | Mar 18, 2022 | Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh... |
| CVE-2022-0547 | CRITICAL | 9.8 | 3.5% | Mar 18, 2022 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than... |
| CVE-2022-24637 | CRITICAL | 9.8 | 99.1% | Mar 18, 2022 | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh... |
| CVE-2022-24773 | MEDIUM | 5.3 | 0.9% | Mar 18, 2022 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ... |
| CVE-2022-24772 | HIGH | 7.5 | 1.0% | Mar 18, 2022 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ... |
| CVE-2022-24771 | HIGH | 7.5 | 0.7% | Mar 18, 2022 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ... |
| CVE-2022-24595 | CRITICAL | 9.8 | 2.0% | Mar 18, 2022 | Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Cont... |
| CVE-2022-0742 | HIGH | 7.5 | 4.9% | Mar 18, 2022 | Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-... |
| CVE-2022-24655 | HIGH | 7.8 | 1.1% | Mar 18, 2022 | A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0... |
| CVE-2022-27191 | HIGH | 7.5 | 3.9% | Mar 18, 2022 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server... |
| CVE-2022-26965 | HIGH | 7.2 | 37.7% | Mar 18, 2022 | In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot... |
| CVE-2022-27240 | CRITICAL | 9.8 | 1.5% | Mar 18, 2022 | scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion. |
| CVE-2022-0758 | MEDIUM | 6.1 | 0.4% | Mar 17, 2022 | Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the share... |
| CVE-2022-0757 | HIGH | 8.8 | 1.2% | Mar 17, 2022 | Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search opera... |
| CVE-2022-0237 | HIGH | 7.8 | 0.5% | Mar 17, 2022 | Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker... |
| CVE-2022-24302 | MEDIUM | 5.9 | 2.1% | Mar 17, 2022 | In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could al... |
| CVE-2022-26504 | HIGH | 8.8 | 2.5% | Mar 17, 2022 | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Cen... |
| CVE-2022-26501 | CRITICAL | 9.8 | 4.3% | Mar 17, 2022 | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). |
| CVE-2022-26500 | HIGH | 8.8 | 5.9% | Mar 17, 2022 | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated ... |
| CVE-2022-24770 | HIGH | 8.8 | 1.2% | Mar 17, 2022 | `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11... |
| CVE-2022-21822 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Re... |
| CVE-2022-26511 | HIGH | 7.8 | 0.6% | Mar 17, 2022 | WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading). |
| CVE-2022-26081 | HIGH | 7.8 | 0.8% | Mar 17, 2022 | The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary co... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now