2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25550 | HIGH | 7.5 | 1.2% | Mar 10, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerabili... |
| CVE-2022-25549 | HIGH | 7.5 | 1.2% | Mar 10, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability ... |
| CVE-2022-25548 | HIGH | 7.5 | 1.2% | Mar 10, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allo... |
| CVE-2022-25547 | HIGH | 7.5 | 8.8% | Mar 10, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allo... |
| CVE-2022-25546 | HIGH | 7.5 | 12.3% | Mar 10, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability ... |
| CVE-2022-25368 | MEDIUM | 4.7 | 0.3% | Mar 10, 2022 | Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to... |
| CVE-2022-25325 | HIGH | 7.8 | 1.0% | Mar 10, 2022 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an atta... |
| CVE-2022-25294 | HIGH | 7.8 | 0.3% | Mar 10, 2022 | Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an u... |
| CVE-2022-25244 | MEDIUM | 6.5 | 0.9% | Mar 10, 2022 | Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenizat... |
| CVE-2022-25243 | MEDIUM | 6.5 | 0.5% | Mar 10, 2022 | "Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations t... |
| CVE-2022-25234 | HIGH | 7.8 | 1.0% | Mar 10, 2022 | Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an... |
| CVE-2022-25230 | HIGH | 7.8 | 1.0% | Mar 10, 2022 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an atta... |
| CVE-2022-25225 | HIGH | 7.2 | 2.8% | Mar 10, 2022 | Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the '... |
| CVE-2022-25219 | HIGH | 8.4 | 0.8% | Mar 10, 2022 | A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair o... |
| CVE-2022-25218 | HIGH | 8.1 | 1.0% | Mar 10, 2022 | The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated at... |
| CVE-2022-25217 | HIGH | 7.8 | 0.3% | Mar 10, 2022 | Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network t... |
| CVE-2022-25215 | MEDIUM | 5.3 | 1.1% | Mar 10, 2022 | Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove)... |
| CVE-2022-25214 | HIGH | 7.4 | 1.5% | Mar 10, 2022 | Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensiti... |
| CVE-2022-25213 | MEDIUM | 6.8 | 0.4% | Mar 10, 2022 | Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical acce... |
| CVE-2022-25108 | MEDIUM | 5.5 | 0.8% | Mar 10, 2022 | Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsi... |
| CVE-2022-25090 | HIGH | 8.1 | 11.0% | Mar 10, 2022 | Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure ... |
| CVE-2022-24995 | CRITICAL | 9.8 | 13.6% | Mar 10, 2022 | Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability ... |
| CVE-2022-24960 | HIGH | 7.8 | 0.6% | Mar 10, 2022 | A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data pr... |
| CVE-2022-24932 | MEDIUM | 4.6 | 0.1% | Mar 10, 2022 | Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physi... |
| CVE-2022-24931 | HIGH | 7.8 | 0.1% | Mar 10, 2022 | Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthori... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now