2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0382 | MEDIUM | 5.5 | 0.4% | Feb 11, 2022 | An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way... |
| CVE-2022-0185 | HIGH | 8.4 | 25.2% | Feb 11, 2022 | A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio... |
| CVE-2022-24289 | HIGH | 8.8 | 2.2% | Feb 11, 2022 | Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Ob... |
| CVE-2022-24112 | CRITICAL | 9.8 | 96.2% | Feb 11, 2022 | An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default co... |
| CVE-2022-0560 | MEDIUM | 6.1 | 1.0% | Feb 11, 2022 | Open Redirect in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0557 | HIGH | 7.2 | 51.2% | Feb 11, 2022 | OS Command Injection in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-24961 | CRITICAL | 9.8 | 1.6% | Feb 11, 2022 | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in... |
| CVE-2022-24959 | MEDIUM | 5.5 | 0.4% | Feb 11, 2022 | An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/h... |
| CVE-2022-24958 | HIGH | 7.8 | 0.4% | Feb 11, 2022 | drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release. |
| CVE-2022-24955 | CRITICAL | 9.8 | 1.0% | Feb 11, 2022 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files... |
| CVE-2022-24954 | CRITICAL | 9.8 | 11.9% | Feb 11, 2022 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for... |
| CVE-2022-23806 | CRITICAL | 9.1 | 3.0% | Feb 11, 2022 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situatio... |
| CVE-2022-23773 | HIGH | 7.5 | 2.7% | Feb 11, 2022 | cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tag... |
| CVE-2022-23772 | HIGH | 7.5 | 2.8% | Feb 11, 2022 | Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Me... |
| CVE-2022-24647 | HIGH | 8.1 | 1.0% | Feb 10, 2022 | Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function. |
| CVE-2022-24646 | HIGH | 7.5 | 1.7% | Feb 10, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m... |
| CVE-2022-0554 | HIGH | 7.8 | 1.7% | Feb 10, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-24916 | HIGH | 7.5 | 1.5% | Feb 10, 2022 | Optimism before @eth-optimism/l2geth@0.5.11 allows economic griefing because a balance is duplicated upon contract self-... |
| CVE-2022-23630 | HIGH | 7.5 | 1.3% | Feb 10, 2022 | Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradl... |
| CVE-2022-24568 | CRITICAL | 9.8 | 1.1% | Feb 10, 2022 | Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. |
| CVE-2022-23321 | MEDIUM | 4.8 | 0.8% | Feb 10, 2022 | A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when ed... |
| CVE-2022-20749 | CRITICAL | 9.8 | 3.9% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20738 | CRITICAL | 9.8 | 1.1% | Feb 10, 2022 | A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypa... |
| CVE-2022-20712 | CRITICAL | 9.8 | 2.9% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20711 | CRITICAL | 9.8 | 4.6% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now