2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24285HIGH7.8Acer Care Center 4.00.30xx before 4.00.3042 contains a local privilege escalation vulnerability. The user process commun...
CVE-2022-24193CRITICAL9.8CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
CVE-2022-24177MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows a...
CVE-2022-23940HIGH8.8SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Sched...
CVE-2022-23383CRITICAL9.1YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page ca...
CVE-2022-22985HIGH8.8The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to in...
CVE-2022-22835MEDIUM6.5An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL ...
CVE-2022-22834HIGH8.8An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test Trasformazione XSL function...
CVE-2022-22814CRITICAL9.8The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
CVE-2022-22795CRITICAL9.1Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can rea...
CVE-2022-22547HIGH7.5Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would othe...
CVE-2022-21219HIGH7.8Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an ...
CVE-2022-21170LOW3.7Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILT...
CVE-2022-21158MEDIUM5.4A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (...
CVE-2022-21146MEDIUM6.1Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arb...
CVE-2022-21132MEDIUM6.5Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfS...
CVE-2022-21124HIGH7.8Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an...
CVE-2022-20060MEDIUM6.6In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead ...
CVE-2022-20059MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20058MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20057MEDIUM6.5In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of p...
CVE-2022-20056MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20055MEDIUM6.8In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20054HIGH7.8In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local esc...
CVE-2022-20053HIGH7.8In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now