2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2948HIGH7.8GE CIMPICITY versions 2022 and prior is vulnerable to a heap-based buffer overflow, which could allow an attacker to e...
CVE-2022-2002HIGH7.8GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gm...
CVE-2022-23491HIGH7.5Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify...
CVE-2022-23487HIGH7.5js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp...
CVE-2022-23486HIGH7.5libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an ...
CVE-2022-46770HIGH7.5qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s...
CVE-2022-44373HIGH8.8A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1...
CVE-2022-43581HIGH8.8IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 i...
CVE-2022-44393HIGH7.2Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/view_service&id=.
CVE-2022-41720HIGH7.5On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide ...
CVE-2022-40966HIGH8.8Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass aut...
CVE-2022-4322HIGH7.2A vulnerability, which was classified as critical, was found in maku-boot up to 2.2.0. This affects the function doExecu...
CVE-2022-44620HIGH8.8Improper authentication vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earli...
CVE-2022-44608HIGH7.5Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated at...
CVE-2022-44606HIGH8.8OS command injection vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ...
CVE-2022-43667HIGH7.8Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disc...
CVE-2022-43660HIGH7.2Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authentic...
CVE-2022-43509HIGH7.8Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure a...
CVE-2022-43508HIGH7.8Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or...
CVE-2022-43468HIGH7.5External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and ea...
CVE-2022-43464HIGH8.8Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ...
CVE-2022-41800HIGH8.7 In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be...
CVE-2022-41622HIGH8.8In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. ...
CVE-2022-44849HIGH8.8A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super ...
CVE-2022-45009HIGH7.2Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/cl...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now