2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25550HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function saveParentControlInfo. This vulnerabili...
CVE-2022-25549HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability ...
CVE-2022-25548HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allo...
CVE-2022-25547HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allo...
CVE-2022-25546HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow in the function formSetSysToolDDNS. This vulnerability ...
CVE-2022-25368MEDIUM4.7Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to...
CVE-2022-25325HIGH7.8Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an atta...
CVE-2022-25294HIGH7.8Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an u...
CVE-2022-25244MEDIUM6.5Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenizat...
CVE-2022-25243MEDIUM6.5"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations t...
CVE-2022-25234HIGH7.8Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an...
CVE-2022-25230HIGH7.8Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an atta...
CVE-2022-25225HIGH7.2Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the '...
CVE-2022-25219HIGH8.4A null byte interaction error has been discovered in the code that the telnetd_startup daemon uses to construct a pair o...
CVE-2022-25218HIGH8.1The use of the RSA algorithm without OAEP, or any other padding scheme, in telnetd_startup, allows an unauthenticated at...
CVE-2022-25217HIGH7.8Use of a hard-coded cryptographic key pair by the telnetd_startup service allows an attacker on the local area network t...
CVE-2022-25215MEDIUM5.3Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove)...
CVE-2022-25214HIGH7.4Improper access control on the LocalClientList.asp interface allows an unauthenticated remote attacker to obtain sensiti...
CVE-2022-25213MEDIUM6.8Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical acce...
CVE-2022-25108MEDIUM5.5Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsi...
CVE-2022-25090HIGH8.1Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure ...
CVE-2022-24995CRITICAL9.8Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability ...
CVE-2022-24960HIGH7.8A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data pr...
CVE-2022-24932MEDIUM4.6Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physi...
CVE-2022-24931HIGH7.8Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthori...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now