2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2665 | HIGH | 8.8 | 0.5% | Aug 5, 2022 | A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerabil... |
| CVE-2022-2636 | HIGH | 8.8 | 1.1% | Aug 5, 2022 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. |
| CVE-2022-2626 | HIGH | 7.2 | 1.0% | Aug 5, 2022 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. |
| CVE-2022-37415 | HIGH | 7.8 | 0.4% | Aug 5, 2022 | The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008. |
| CVE-2022-37030 | HIGH | 7.8 | 0.3% | Aug 4, 2022 | Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a loc... |
| CVE-2022-35930 | HIGH | 8.8 | 0.5% | Aug 4, 2022 | PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 Pol... |
| CVE-2022-31793 | HIGH | 7.5 | 11.4% | Aug 4, 2022 | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi... |
| CVE-2022-35926 | HIGH | 7.5 | 0.9% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv... |
| CVE-2022-35858 | HIGH | 7.8 | 0.4% | Aug 4, 2022 | The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to tr... |
| CVE-2022-35142 | HIGH | 7.5 | 1.2% | Aug 4, 2022 | An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the S... |
| CVE-2022-35735 | HIGH | 7.2 | 0.8% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, a... |
| CVE-2022-35245 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access ... |
| CVE-2022-35240 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (M... |
| CVE-2022-35236 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is co... |
| CVE-2022-34862 | HIGH | 7.5 | 1.1% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, whe... |
| CVE-2022-34844 | HIGH | 7.5 | 0.6% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plan... |
| CVE-2022-34655 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing th... |
| CVE-2022-34651 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS ... |
| CVE-2022-33203 | HIGH | 7.5 | 0.7% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access poli... |
| CVE-2022-32455 | HIGH | 7.5 | 0.4% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, whe... |
| CVE-2022-31473 | HIGH | 7.7 | 1.8% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attac... |
| CVE-2022-35216 | HIGH | 7.5 | 1.1% | Aug 4, 2022 | OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can explo... |
| CVE-2022-32963 | HIGH | 7.5 | 1.1% | Aug 4, 2022 | OMICARD EDM’s mail file relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploi... |
| CVE-2022-34158 | HIGH | 8.8 | 1.1% | Aug 4, 2022 | A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, ... |
| CVE-2022-35506 | HIGH | 7.5 | 0.8% | Aug 3, 2022 | TripleCross v0.1.0 was discovered to contain a stack overflow which occurs because there is no limit to the length of pr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now