2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34440CRITICAL9.8Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabili...
CVE-2022-23814MEDIUM5.3Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest...
CVE-2022-23813MEDIUM5.3The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of i...
CVE-2022-42271HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-0553MEDIUM4.6There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means...
CVE-2022-48253CRITICAL9.8nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands...
CVE-2022-48252CRITICAL9.8The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)...
CVE-2022-43393HIGH8.2An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 fir...
CVE-2022-43392MEDIUM6.5A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which ...
CVE-2022-43391MEDIUM6.5A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, w...
CVE-2022-43390HIGH8.8A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allo...
CVE-2022-43389CRITICAL9.8A buffer overflow vulnerability in the library of the web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, whic...
CVE-2022-4382MEDIUM6.4A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could ...
CVE-2022-4379HIGH7.5A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allow...
CVE-2022-4338CRITICAL9.8An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.
CVE-2022-4337CRITICAL9.8An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.
CVE-2022-46449HIGH7.5An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2022-46163HIGH7.5Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank...
CVE-2022-45167MEDIUM4.3An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user...
CVE-2022-45166MEDIUM4.3An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a set of us...
CVE-2022-45165HIGH8.8An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application accepts a user-cont...
CVE-2022-45164MEDIUM4.3An issue was discovered in Archibus Web Central 2022.03.01.107. A service exposed by the application allows a basic user...
CVE-2022-38492HIGH8.8An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022....
CVE-2022-38491HIGH7.5An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protec...
CVE-2022-38490HIGH8.8An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now