2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45597CRITICAL9.8ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability b...
CVE-2022-42528MEDIUM5.5In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local infor...
CVE-2022-42500MEDIUM6.7In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l...
CVE-2022-42499CRITICAL9.8In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. T...
CVE-2022-42498CRITICAL9.8In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to re...
CVE-2022-40208MEDIUM4.3In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigat...
CVE-2022-20542HIGH7.8In parseParamsBlob of types.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead ...
CVE-2022-20532CRITICAL9.8In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. Thi...
CVE-2022-20499MEDIUM5.5In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to loca...
CVE-2022-20467MEDIUM5.5In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. Th...
CVE-2022-47502HIGH7.8Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes ar...
CVE-2022-38745HIGH7.8Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead t...
CVE-2022-42948CRITICAL9.8Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted...
CVE-2022-28495CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebW...
CVE-2022-3146MEDIUM5.5A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n...
CVE-2022-3101MEDIUM5.5A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n...
CVE-2022-36413CRITICAL9.1Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset o...
CVE-2022-47145MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3...
CVE-2022-28496CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswor...
CVE-2022-47173MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Goog...
CVE-2022-28497CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_wri...
CVE-2022-47589MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <...
CVE-2022-28493CRITICAL9.8A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,
CVE-2022-28491CRITICAL9.8TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost functio...
CVE-2022-28492CRITICAL9.8TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now