2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38368 | HIGH | 8.8 | 0.7% | Aug 15, 2022 | An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mis... |
| CVE-2022-2816 | HIGH | 7.8 | 0.5% | Aug 15, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212. |
| CVE-2022-38187 | HIGH | 7.5 | 0.6% | Aug 15, 2022 | Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, whi... |
| CVE-2022-35822 | HIGH | 7.1 | 0.8% | Aug 15, 2022 | Windows Defender Credential Guard Security Feature Bypass Vulnerability |
| CVE-2022-34711 | HIGH | 7.8 | 0.7% | Aug 15, 2022 | Windows Defender Credential Guard Elevation of Privilege Vulnerability |
| CVE-2022-36526 | HIGH | 7.5 | 1.3% | Aug 15, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via functi... |
| CVE-2022-36524 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /... |
| CVE-2022-35624 | HIGH | 8.8 | 0.9% | Aug 15, 2022 | In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets... |
| CVE-2022-35623 | HIGH | 8.8 | 0.9% | Aug 15, 2022 | In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control... |
| CVE-2022-33990 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning becaus... |
| CVE-2022-33988 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attacker... |
| CVE-2022-33992 | HIGH | 7.5 | 0.8% | Aug 15, 2022 | DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set t... |
| CVE-2022-38223 | HIGH | 7.8 | 0.4% | Aug 15, 2022 | There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTM... |
| CVE-2022-37401 | HIGH | 8.8 | 1.4% | Aug 15, 2022 | Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored... |
| CVE-2022-37400 | HIGH | 8.8 | 0.8% | Aug 15, 2022 | Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored... |
| CVE-2022-36006 | HIGH | 8.8 | 1.3% | Aug 15, 2022 | Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedic... |
| CVE-2022-2822 | HIGH | 7.5 | 0.7% | Aug 15, 2022 | An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess us... |
| CVE-2022-2821 | HIGH | 7.5 | 1.1% | Aug 15, 2022 | Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. |
| CVE-2022-2820 | HIGH | 8.2 | 0.6% | Aug 15, 2022 | Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. |
| CVE-2022-2819 | HIGH | 7.8 | 0.5% | Aug 15, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. |
| CVE-2022-2818 | HIGH | 8.8 | 1.3% | Aug 15, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.... |
| CVE-2022-2813 | HIGH | 7.5 | 0.4% | Aug 15, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is a... |
| CVE-2022-2381 | HIGH | 8.8 | 0.4% | Aug 15, 2022 | The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School ... |
| CVE-2022-2379 | HIGH | 7.5 | 2.8% | Aug 15, 2022 | The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us... |
| CVE-2022-2354 | HIGH | 7.2 | 1.0% | Aug 15, 2022 | The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the s... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now