2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2000 | HIGH | 7.8 | 1.5% | Jun 9, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-23138 | HIGH | 7.5 | 0.9% | Jun 9, 2022 | ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the d... |
| CVE-2022-1998 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_recor... |
| CVE-2022-31026 | HIGH | 7.5 | 1.0% | Jun 9, 2022 | Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authenti... |
| CVE-2022-31019 | HIGH | 7.5 | 1.5% | Jun 9, 2022 | Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request b... |
| CVE-2022-29255 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling ... |
| CVE-2022-31649 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. |
| CVE-2022-30075 | HIGH | 8.8 | 37.2% | Jun 9, 2022 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote... |
| CVE-2022-25806 | HIGH | 8.8 | 0.9% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredenti... |
| CVE-2022-31496 | HIGH | 8.8 | 1.9% | Jun 9, 2022 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. |
| CVE-2022-29014 | HIGH | 7.5 | 10.6% | Jun 9, 2022 | A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary... |
| CVE-2022-31325 | HIGH | 7.2 | 5.0% | Jun 8, 2022 | There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. |
| CVE-2022-28382 | HIGH | 7.5 | 1.6% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode... |
| CVE-2022-24296 | HIGH | 7.5 | 1.1% | Jun 8, 2022 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, A... |
| CVE-2022-30790 | HIGH | 7.8 | 0.6% | Jun 8, 2022 | Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. |
| CVE-2022-1683 | HIGH | 8.8 | 1.5% | Jun 8, 2022 | The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement... |
| CVE-2022-1703 | HIGH | 8.8 | 11.1% | Jun 8, 2022 | Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote ... |
| CVE-2022-30749 | HIGH | 7.8 | 0.2% | Jun 7, 2022 | Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart d... |
| CVE-2022-30746 | HIGH | 7.5 | 0.8% | Jun 7, 2022 | Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely ... |
| CVE-2022-30744 | HIGH | 7.8 | 0.2% | Jun 7, 2022 | DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arb... |
| CVE-2022-30735 | HIGH | 7.5 | 0.4% | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_tok... |
| CVE-2022-30732 | HIGH | 7.5 | 0.6% | Jun 7, 2022 | Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access ... |
| CVE-2022-30726 | HIGH | 7.8 | 0.1% | Jun 7, 2022 | Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1... |
| CVE-2022-30717 | HIGH | 7.5 | 0.2% | Jun 7, 2022 | Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera funct... |
| CVE-2022-1708 | HIGH | 7.5 | 2.8% | Jun 7, 2022 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now