2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0559 | CRITICAL | 9.8 | 1.2% | Feb 16, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. |
| CVE-2022-25236 | CRITICAL | 9.8 | 33.9% | Feb 16, 2022 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace... |
| CVE-2022-25235 | CRITICAL | 9.8 | 4.9% | Feb 16, 2022 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT... |
| CVE-2022-22770 | CRITICAL | 9.8 | 1.1% | Feb 15, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allo... |
| CVE-2022-25139 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. |
| CVE-2022-24705 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recv... |
| CVE-2022-24704 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby... |
| CVE-2022-23992 | CRITICAL | 9.8 | 2.3% | Feb 14, 2022 | XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validat... |
| CVE-2022-0582 | CRITICAL | 9.8 | 2.0% | Feb 14, 2022 | Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of servic... |
| CVE-2022-24206 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LI... |
| CVE-2022-23902 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter. |
| CVE-2022-23390 | CRITICAL | 9.8 | 1.4% | Feb 14, 2022 | An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. |
| CVE-2022-23389 | CRITICAL | 9.8 | 22.0% | Feb 14, 2022 | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. |
| CVE-2022-23337 | CRITICAL | 9.8 | 2.3% | Feb 14, 2022 | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parame... |
| CVE-2022-23336 | CRITICAL | 9.8 | 1.1% | Feb 14, 2022 | S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. |
| CVE-2022-23335 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParamet... |
| CVE-2022-22295 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para p... |
| CVE-2022-24988 | CRITICAL | 9.8 | 1.1% | Feb 14, 2022 | In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector. |
| CVE-2022-24977 | CRITICAL | 9.8 | 6.5% | Feb 14, 2022 | ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or ima... |
| CVE-2022-24976 | CRITICAL | 9.1 | 1.8% | Feb 14, 2022 | Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC... |
| CVE-2022-0570 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | Heap-based Buffer Overflow in Homebrew mruby prior to 3.2. |
| CVE-2022-0290 | CRITICAL | 9.6 | 2.0% | Feb 12, 2022 | Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform... |
| CVE-2022-0097 | CRITICAL | 9.6 | 0.9% | Feb 12, 2022 | Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user... |
| CVE-2022-24927 | CRITICAL | 9.8 | 0.3% | Feb 11, 2022 | Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execu... |
| CVE-2022-23425 | CRITICAL | 9.8 | 0.4% | Feb 11, 2022 | Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS sign... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now