2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2892 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-... |
| CVE-2022-36582 | HIGH | 7.2 | 1.1% | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 a... |
| CVE-2022-36581 | HIGH | 7.5 | 0.8% | Aug 31, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /a... |
| CVE-2022-36580 | HIGH | 7.2 | 1.1% | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering Sys... |
| CVE-2022-36571 | HIGH | 7.2 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the mask parameter at /goform/WanParameterSetting. |
| CVE-2022-36570 | HIGH | 7.2 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the time parameter at /goform/SetLEDCfg. |
| CVE-2022-36569 | HIGH | 8.8 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCf... |
| CVE-2022-36568 | HIGH | 8.8 | 0.9% | Aug 31, 2022 | Tenda AC9 V15.03.05.19 was discovered to contain a stack overflow via the list parameter at /goform/setPptpUserList. |
| CVE-2022-34383 | HIGH | 8.2 | 0.5% | Aug 31, 2022 | Dell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A loca... |
| CVE-2022-34373 | HIGH | 7.8 | 0.2% | Aug 31, 2022 | Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability... |
| CVE-2022-31233 | HIGH | 8 | 0.3% | Aug 31, 2022 | Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user... |
| CVE-2022-37184 | HIGH | 8.8 | 1.0% | Aug 31, 2022 | The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authe... |
| CVE-2022-38152 | HIGH | 7.5 | 2.1% | Aug 31, 2022 | An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is cal... |
| CVE-2022-3028 | HIGH | 7 | 0.2% | Aug 31, 2022 | A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple ca... |
| CVE-2022-37122 | HIGH | 7.5 | 18.2% | Aug 31, 2022 | Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 s... |
| CVE-2022-2866 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a ... |
| CVE-2022-2759 | HIGH | 8.6 | 1.0% | Aug 31, 2022 | Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions w... |
| CVE-2022-2590 | HIGH | 7 | 0.9% | Aug 31, 2022 | A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of pr... |
| CVE-2022-2485 | HIGH | 7.5 | 0.4% | Aug 31, 2022 | Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device resp... |
| CVE-2022-2132 | HIGH | 8.6 | 1.7% | Aug 31, 2022 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of ser... |
| CVE-2022-2044 | HIGH | 8.2 | 0.6% | Aug 31, 2022 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite ... |
| CVE-2022-2043 | HIGH | 7.5 | 0.7% | Aug 31, 2022 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unre... |
| CVE-2022-2006 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code... |
| CVE-2022-2005 | HIGH | 7.5 | 0.4% | Aug 31, 2022 | AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server... |
| CVE-2022-2004 | HIGH | 7.5 | 0.8% | Aug 31, 2022 | AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to preven... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now