2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27664 | HIGH | 7.5 | 2.5% | Sep 6, 2022 | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 conn... |
| CVE-2022-27491 | HIGH | 7.5 | 1.2% | Sep 6, 2022 | A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7... |
| CVE-2022-26469 | HIGH | 7.8 | 0.2% | Sep 6, 2022 | In MtkEmail, there is a possible escalation of privilege due to fragment injection. This could lead to local escalation ... |
| CVE-2022-25308 | HIGH | 7.8 | 0.5% | Sep 6, 2022 | A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially cr... |
| CVE-2022-23684 | HIGH | 8.8 | 1.0% | Sep 6, 2022 | A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only p... |
| CVE-2022-23683 | HIGH | 7.2 | 1.6% | Sep 6, 2022 | Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful... |
| CVE-2022-23682 | HIGH | 7.8 | 0.7% | Sep 6, 2022 | Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ... |
| CVE-2022-23681 | HIGH | 7.8 | 0.6% | Sep 6, 2022 | Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ... |
| CVE-2022-23680 | HIGH | 8.8 | 0.4% | Sep 6, 2022 | AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac... |
| CVE-2022-23679 | HIGH | 8.8 | 0.4% | Sep 6, 2022 | AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac... |
| CVE-2022-23451 | HIGH | 8.1 | 1.0% | Sep 6, 2022 | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any ... |
| CVE-2022-40112 | HIGH | 7.5 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in bin... |
| CVE-2022-40110 | HIGH | 7.5 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa. |
| CVE-2022-37841 | HIGH | 7.5 | 0.6% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. |
| CVE-2022-31020 | HIGH | 8.8 | 1.7% | Sep 6, 2022 | Indy Node is the server portion of a distributed ledger purpose-built for decentralized identity. In versions 1.12.4 and... |
| CVE-2022-2901 | HIGH | 7.1 | 0.5% | Sep 6, 2022 | Improper Authorization in GitHub repository chatwoot/chatwoot prior to 2.8. |
| CVE-2022-34883 | HIGH | 8.8 | 1.2% | Sep 6, 2022 | OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users... |
| CVE-2022-39838 | HIGH | 8.6 | 1.5% | Sep 5, 2022 | Systematic FIX Adapter (ALFAFX) 2.4.0.25 13/09/2017 allows remote file inclusion via a UNC share pathname, and also allo... |
| CVE-2022-30331 | HIGH | 8.8 | 0.9% | Sep 5, 2022 | The User-Defined Functions (UDF) feature in TigerGraph 3.6.0 allows installation of a query (in the GSQL query language)... |
| CVE-2022-3121 | HIGH | 8.8 | 0.2% | Sep 5, 2022 | A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problem... |
| CVE-2022-2565 | HIGH | 7.2 | 0.6% | Sep 5, 2022 | The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given... |
| CVE-2022-2083 | HIGH | 7.5 | 0.6% | Sep 5, 2022 | The Simple Single Sign On WordPress plugin through 4.1.0 leaks its OAuth client_secret, which could be used by attackers... |
| CVE-2022-38370 | HIGH | 7.5 | 1.1% | Sep 5, 2022 | Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal... |
| CVE-2022-38369 | HIGH | 8.8 | 1.1% | Sep 5, 2022 | Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses t... |
| CVE-2022-3008 | HIGH | 8.8 | 2.8% | Sep 5, 2022 | The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are pr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now