2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32323 | HIGH | 7.3 | 0.8% | Jul 14, 2022 | AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. |
| CVE-2022-32298 | HIGH | 7.5 | 0.9% | Jul 14, 2022 | Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lea... |
| CVE-2022-32297 | HIGH | 7.5 | 1.0% | Jul 14, 2022 | Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. |
| CVE-2022-31147 | HIGH | 7.5 | 1.6% | Jul 14, 2022 | The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation pr... |
| CVE-2022-31142 | HIGH | 7.5 | 1.2% | Jul 14, 2022 | @fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions... |
| CVE-2022-22460 | HIGH | 7.5 | 0.6% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be use... |
| CVE-2022-22453 | HIGH | 7.5 | 0.3% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacke... |
| CVE-2022-22452 | HIGH | 7.5 | 0.8% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker ... |
| CVE-2022-32223 | HIGH | 7.3 | 1.6% | Jul 14, 2022 | Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnera... |
| CVE-2022-32212 | HIGH | 8.1 | 5.6% | Jul 14, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAll... |
| CVE-2022-28876 | HIGH | 7.5 | 0.4% | Jul 14, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the... |
| CVE-2022-30024 | HIGH | 8.8 | 2.2% | Jul 14, 2022 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated... |
| CVE-2022-28377 | HIGH | 7.5 | 0.8% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28374 | HIGH | 8.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DM... |
| CVE-2022-28372 | HIGH | 7.5 | 0.7% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28371 | HIGH | 7.5 | 0.5% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28370 | HIGH | 7.5 | 0.3% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of pr... |
| CVE-2022-34764 | HIGH | 7.5 | 0.6% | Jul 13, 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause... |
| CVE-2022-34763 | HIGH | 7.5 | 0.3% | Jul 13, 2022 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized ... |
| CVE-2022-34762 | HIGH | 7.5 | 0.6% | Jul 13, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could... |
| CVE-2022-34761 | HIGH | 7.5 | 0.8% | Jul 13, 2022 | A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when pars... |
| CVE-2022-34760 | HIGH | 7.5 | 0.7% | Jul 13, 2022 | A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of serv... |
| CVE-2022-34759 | HIGH | 7.5 | 0.7% | Jul 13, 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to imprope... |
| CVE-2022-34753 | HIGH | 8.8 | 71.1% | Jul 13, 2022 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist... |
| CVE-2022-32117 | HIGH | 7.8 | 0.3% | Jul 13, 2022 | Jerryscript v2.4.0 was discovered to contain a stack buffer overflow via the function jerryx_print_unhandled_exception i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now