2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38368HIGH8.8An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mis...
CVE-2022-2816HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
CVE-2022-38187HIGH7.5Prior to version 10.9.0, the sharing/rest/content/features/analyze endpoint is always accessible to anonymous users, whi...
CVE-2022-35822HIGH7.1Windows Defender Credential Guard Security Feature Bypass Vulnerability
CVE-2022-34711HIGH7.8Windows Defender Credential Guard Elevation of Privilege Vulnerability
CVE-2022-36526HIGH7.5D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via functi...
CVE-2022-36524HIGH7.5D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /...
CVE-2022-35624HIGH8.8In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets...
CVE-2022-35623HIGH8.8In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control...
CVE-2022-33990HIGH7.5Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning becaus...
CVE-2022-33988HIGH7.5dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attacker...
CVE-2022-33992HIGH7.5DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set t...
CVE-2022-38223HIGH7.8There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTM...
CVE-2022-37401HIGH8.8Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored...
CVE-2022-37400HIGH8.8Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored...
CVE-2022-36006HIGH8.8Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedic...
CVE-2022-2822HIGH7.5An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess us...
CVE-2022-2821HIGH7.5Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2820HIGH8.2Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
CVE-2022-2819HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
CVE-2022-2818HIGH8.8Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2....
CVE-2022-2813HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Guest Management System. Affected is a...
CVE-2022-2381HIGH8.8The E Unlocked - Student Result WordPress plugin through 1.0.4 is lacking CSRF and validation when uploading the School ...
CVE-2022-2379HIGH7.5The Easy Student Results WordPress plugin through 2.2.8 lacks authorisation in its REST API, allowing unauthenticated us...
CVE-2022-2354HIGH7.2The WP-DBManager WordPress plugin before 2.80.8 does not prevent administrators from running arbitrary commands on the s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now