2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-31766HIGH8.6A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDC...
CVE-2022-31765HIGH8.8Affected devices do not properly authorize the change password function of the web interface. This could allow low priv...
CVE-2022-41749HIGH7.8An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile...
CVE-2022-41747HIGH7.8An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a...
CVE-2022-41745HIGH7An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted...
CVE-2022-41744HIGH7A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul...
CVE-2022-3154HIGH7.1The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before ...
CVE-2022-39288HIGH7.5fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of s...
CVE-2022-34425HIGH7.5Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An unauthenticated remote atta...
CVE-2022-20920HIGH7.7A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, ...
CVE-2022-20915HIGH7.4A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Softw...
CVE-2022-20870HIGH8.6A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst...
CVE-2022-20837HIGH8.6A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NA...
CVE-2022-39292HIGH7.5Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitiv...
CVE-2022-42725HIGH7.5Warpinator through 1.2.14 allows access outside of an intended directory, as demonstrated by symbolic directory links.
CVE-2022-3436HIGH7.5A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t...
CVE-2022-36635HIGH8.8ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do...
CVE-2022-39959HIGH7.8Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol...
CVE-2022-41574HIGH7.5An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups ...
CVE-2022-3276HIGH8.8Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to explo...
CVE-2022-39289HIGH7.5ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP...
CVE-2022-36634HIGH8.8An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a c...
CVE-2022-32591HIGH7.5In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service w...
CVE-2022-32589HIGH7.5In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to rem...
CVE-2022-26472HIGH7.8In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now