2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2319 | HIGH | 7.8 | 0.4% | Sep 1, 2022 | A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due ... |
| CVE-2022-1902 | HIGH | 8.8 | 1.1% | Sep 1, 2022 | A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i... |
| CVE-2022-1729 | HIGH | 7 | 0.3% | Sep 1, 2022 | A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain ... |
| CVE-2022-36773 | HIGH | 8.1 | 1.4% | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when proc... |
| CVE-2022-34380 | HIGH | 8.2 | 0.2% | Sep 1, 2022 | Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulner... |
| CVE-2022-30614 | HIGH | 7.5 | 1.3% | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sendin... |
| CVE-2022-2996 | HIGH | 7.4 | 0.5% | Sep 1, 2022 | A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate wou... |
| CVE-2022-36373 | HIGH | 8.8 | 0.4% | Sep 1, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress. |
| CVE-2022-37435 | HIGH | 8.8 | 1.1% | Sep 1, 2022 | Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi... |
| CVE-2022-36054 | HIGH | 8.8 | 0.6% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio... |
| CVE-2022-36053 | HIGH | 8.8 | 0.5% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 networ... |
| CVE-2022-36052 | HIGH | 8.8 | 0.5% | Sep 1, 2022 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio... |
| CVE-2022-36676 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate... |
| CVE-2022-36675 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche... |
| CVE-2022-36674 | HIGH | 7.2 | 0.8% | Sep 1, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche... |
| CVE-2022-36671 | HIGH | 7.5 | 0.4% | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download AP... |
| CVE-2022-37129 | HIGH | 8.8 | 8.3% | Aug 31, 2022 | D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in ... |
| CVE-2022-37123 | HIGH | 8.8 | 2.7% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi. |
| CVE-2022-36619 | HIGH | 7.5 | 1.0% | Aug 31, 2022 | In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC. |
| CVE-2022-36051 | HIGH | 8.8 | 0.8% | Aug 31, 2022 | ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the ... |
| CVE-2022-36620 | HIGH | 7.5 | 23.2% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting. |
| CVE-2022-2897 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow... |
| CVE-2022-2896 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. |
| CVE-2022-2895 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based ... |
| CVE-2022-2894 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted po... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now