2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-27664HIGH7.5In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 conn...
CVE-2022-27491HIGH7.5A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7...
CVE-2022-26469HIGH7.8In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation ...
CVE-2022-25308HIGH7.8A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially cr...
CVE-2022-23684HIGH8.8A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only p...
CVE-2022-23683HIGH7.2Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful...
CVE-2022-23682HIGH7.8Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ...
CVE-2022-23681HIGH7.8Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ...
CVE-2022-23680HIGH8.8AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac...
CVE-2022-23679HIGH8.8AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac...
CVE-2022-23451HIGH8.1An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any ...
CVE-2022-40112HIGH7.5TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in bin...
CVE-2022-40110HIGH7.5TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa.
CVE-2022-37841HIGH7.5In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample.
CVE-2022-31020HIGH8.8Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and...
CVE-2022-2901HIGH7.1Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8.
CVE-2022-34883HIGH8.8OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users...
CVE-2022-39838HIGH8.6Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allo...
CVE-2022-30331HIGH8.8The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language)...
CVE-2022-3121HIGH8.8A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problem...
CVE-2022-2565HIGH7.2The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given...
CVE-2022-2083HIGH7.5The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers...
CVE-2022-38370HIGH7.5Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal...
CVE-2022-38369HIGH8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses t...
CVE-2022-3008HIGH8.8The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are pr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now