2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0547 | CRITICAL | 9.8 | 3.5% | Mar 18, 2022 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than... |
| CVE-2022-24637 | CRITICAL | 9.8 | 99.1% | Mar 18, 2022 | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, wh... |
| CVE-2022-24595 | CRITICAL | 9.8 | 2.0% | Mar 18, 2022 | Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected by Incorrect Access Cont... |
| CVE-2022-27240 | CRITICAL | 9.8 | 1.5% | Mar 18, 2022 | scheme/webauthn.c in Glewlwyd SSO server 2.x before 2.6.2 has a buffer overflow associated with a webauthn assertion. |
| CVE-2022-26501 | CRITICAL | 9.8 | 4.3% | Mar 17, 2022 | Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2). |
| CVE-2022-25760 | CRITICAL | 9.8 | 1.6% | Mar 17, 2022 | All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructo... |
| CVE-2022-25354 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to ... |
| CVE-2022-25352 | CRITICAL | 9.8 | 2.0% | Mar 17, 2022 | The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** Thi... |
| CVE-2022-0749 | CRITICAL | 9.8 | 1.7% | Mar 17, 2022 | This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the... |
| CVE-2022-0748 | CRITICAL | 9.8 | 2.0% | Mar 17, 2022 | The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe ... |
| CVE-2022-1000 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. |
| CVE-2022-24074 | CRITICAL | 9.8 | 1.0% | Mar 17, 2022 | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from t... |
| CVE-2022-22273 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure R... |
| CVE-2022-26293 | CRITICAL | 9.8 | 2.2% | Mar 16, 2022 | Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ... |
| CVE-2022-23812 | CRITICAL | 9.8 | 4.2% | Mar 16, 2022 | This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets user... |
| CVE-2022-25251 | CRITICAL | 9.8 | 1.8% | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all... |
| CVE-2022-25247 | CRITICAL | 9.8 | 3.9% | Mar 16, 2022 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain com... |
| CVE-2022-0982 | CRITICAL | 9.8 | 1.2% | Mar 16, 2022 | The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereb... |
| CVE-2022-27005 | CRITICAL | 9.8 | 5.5% | Mar 15, 2022 | Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ... |
| CVE-2022-27004 | CRITICAL | 9.8 | 2.9% | Mar 15, 2022 | Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ... |
| CVE-2022-27003 | CRITICAL | 9.8 | 2.9% | Mar 15, 2022 | Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command ... |
| CVE-2022-27002 | CRITICAL | 9.8 | 6.1% | Mar 15, 2022 | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name... |
| CVE-2022-27001 | CRITICAL | 9.8 | 3.5% | Mar 15, 2022 | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname ... |
| CVE-2022-27000 | CRITICAL | 9.8 | 3.5% | Mar 15, 2022 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via ... |
| CVE-2022-26999 | CRITICAL | 9.8 | 3.5% | Mar 15, 2022 | Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now