2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24112 | CRITICAL | 9.8 | 96.2% | Feb 11, 2022 | An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default co... |
| CVE-2022-24961 | CRITICAL | 9.8 | 1.6% | Feb 11, 2022 | In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in... |
| CVE-2022-24955 | CRITICAL | 9.8 | 1.0% | Feb 11, 2022 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files... |
| CVE-2022-24954 | CRITICAL | 9.8 | 11.9% | Feb 11, 2022 | Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for... |
| CVE-2022-23806 | CRITICAL | 9.1 | 3.0% | Feb 11, 2022 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situatio... |
| CVE-2022-24568 | CRITICAL | 9.8 | 1.1% | Feb 10, 2022 | Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. |
| CVE-2022-20749 | CRITICAL | 9.8 | 3.9% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20738 | CRITICAL | 9.8 | 1.1% | Feb 10, 2022 | A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypa... |
| CVE-2022-20712 | CRITICAL | 9.8 | 2.9% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20711 | CRITICAL | 9.8 | 4.6% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20705 | CRITICAL | 9.8 | 80.0% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20700 | CRITICAL | 9.8 | 5.4% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-20699 | CRITICAL | 9.8 | 72.5% | Feb 10, 2022 | Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t... |
| CVE-2022-24313 | CRITICAL | 9.8 | 44.6% | Feb 9, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflo... |
| CVE-2022-24312 | CRITICAL | 9.8 | 3.2% | Feb 9, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification... |
| CVE-2022-24311 | CRITICAL | 9.8 | 3.3% | Feb 9, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification... |
| CVE-2022-24310 | CRITICAL | 9.8 | 2.1% | Feb 9, 2022 | A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to d... |
| CVE-2022-22813 | CRITICAL | 9.8 | 1.1% | Feb 9, 2022 | A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key a... |
| CVE-2022-22810 | CRITICAL | 9.8 | 1.1% | Feb 9, 2022 | A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker t... |
| CVE-2022-22544 | CRITICAL | 9.1 | 1.3% | Feb 9, 2022 | Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all c... |
| CVE-2022-22536 | CRITICAL | 10 | 97.9% | Feb 9, 2022 | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and... |
| CVE-2022-22532 | CRITICAL | 9.8 | 2.3% | Feb 9, 2022 | In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, ... |
| CVE-2022-0162 | CRITICAL | 9.8 | 0.7% | Feb 9, 2022 | The vulnerability exists in TP-Link TL-WR841N V11 3.16.9 Build 160325 Rel.62500n wireless router due to transmission of ... |
| CVE-2022-23631 | CRITICAL | 9.8 | 2.3% | Feb 9, 2022 | superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.... |
| CVE-2022-0525 | CRITICAL | 9.1 | 1.2% | Feb 9, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now